Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 37317

Summary: RTC Vulnerability Tracker Bug
Product: Gentoo Linux Reporter: Tim Yamin (RETIRED) <plasmaroo>
Component: [OLD] UnspecifiedAssignee: x86-kernel (DEPRECATED) <x86-kernel>
Status: RESOLVED FIXED    
Severity: blocker CC: m.debruijne, security
Priority: Highest    
Version: unspecified   
Hardware: All   
OS: All   
Whiteboard:
Package list:
Runtime testing required: ---
Attachments: Patch
Patch for 2.4.20

Description Tim Yamin (RETIRED) gentoo-dev 2004-01-05 11:13:53 UTC
Please append status with the RTC vulnerability bug here. I'm currently working on a GLSA.

For those who need a patch location, see the patch-2.4.24.bz2 tarball: I'll attach a patch in a minute or two...
Comment 1 Tim Yamin (RETIRED) gentoo-dev 2004-01-05 11:18:29 UTC
Created attachment 23201 [details, diff]
Patch

This is from patch-2.4.24.bz2 - all irrelevant stuff including the memory
problem has been removed. It should apply cleanly on all 2.4 kernels providing
none of the patched areas have been patched over previously. I recommend that
this patch is applied after all the other patches, and rediff'ed if needed for
your kernel.
Comment 2 solar (RETIRED) gentoo-dev 2004-01-05 11:24:56 UTC
Thank you for splitting these apart. It will make it much eaiser to get these fixes out quickly.
Comment 3 Andrea Luzzardi 2004-01-05 11:39:56 UTC
Applied this patch to hardened-sources-2.4.22-r2
Comment 4 Tim Yamin (RETIRED) gentoo-dev 2004-01-05 14:24:33 UTC
Fixed aa-sources-2.4.23-r1.ebuild.
Comment 5 Tim Yamin (RETIRED) gentoo-dev 2004-01-05 15:07:56 UTC
Fixed grsec-sources-2.4.23.1.9.13.ebuild and grsec-sources-2.4.23.2.0_rc4.ebuild.
Comment 6 Tim Yamin (RETIRED) gentoo-dev 2004-01-05 16:31:29 UTC
Bumped to and fixed in wolk-sources-4.10_pre7-r2.ebuild and wolk-sources-4.9-r3.ebuild.
Comment 7 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 07:18:47 UTC
Fixed in gentoo-sources-2.4.22-r2.ebuild and gentoo-sources-2.4.20-r10.ebuild.
Comment 8 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 07:51:19 UTC
Fixed in ac-sources-2.4.22-r4.ebuild...
Comment 9 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 07:51:27 UTC
Created attachment 23238 [details, diff]
Patch for 2.4.20
Comment 10 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 08:17:39 UTC
Fixed in alpha-sources-*.ebuild.
Comment 11 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 08:42:09 UTC
Fixed in arm-sources-2.4.19-r2.ebuild.
Comment 12 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 08:55:50 UTC
Fixed in mips-sources-*.ebuild.
Comment 13 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 10:01:15 UTC
Fixed in ck-sources-*.ebuild.
Comment 14 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 14:45:25 UTC
Fixed in ia64-sources-2.4.22-r2.ebuild...
Comment 15 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 14:45:37 UTC
Fixed in openmosix-*.ebuild.
Comment 16 Tim Yamin (RETIRED) gentoo-dev 2004-01-06 16:43:18 UTC
Fixed in rsbac-sources-2.4.20-r1.ebuild.
Comment 17 Tim Yamin (RETIRED) gentoo-dev 2004-01-09 03:54:25 UTC
All vulnerable kernels have been patched. The GLSA went out at around 23:50UTC yesterday, so this is resolved.