From ${URL} : Description OpenVZ has issued an update for kernel. This fixes multiple vulnerabilities, which can be exploited by malicious, local users in a guest virtual machine to cause a DoS (Denial of Service) and by malicious, local users to gain escalated privileges. For more information: SA55348 SA56020 (#2) Solution: Update kernel branch RHEL6 to 042stab085.17. Original Advisory: OpenVZ: http://wiki.openvz.org/Download/kernel/rhel6/042stab085.17 @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
*openvz-sources-2.6.32.85.17 (15 Mar 2014) 15 Mar 2014; Maxim Koltsov <maksbotan@gentoo.org> +openvz-sources-2.6.32.85.17.ebuild: Bump to 2.6.32.85.17, thanks to slepnoga.
(In reply to Andreis Vinogradovs ( slepnoga ) from comment #1) > *openvz-sources-2.6.32.85.17 (15 Mar 2014) > > 15 Mar 2014; Maxim Koltsov <maksbotan@gentoo.org> > +openvz-sources-2.6.32.85.17.ebuild: > Bump to 2.6.32.85.17, thanks to slepnoga. ready to go stable?
(In reply to Mikle Kolyada from comment #2) > (In reply to Andreis Vinogradovs ( slepnoga ) from comment #1) > > *openvz-sources-2.6.32.85.17 (15 Mar 2014) > > > > 15 Mar 2014; Maxim Koltsov <maksbotan@gentoo.org> > > +openvz-sources-2.6.32.85.17.ebuild: > > Bump to 2.6.32.85.17, thanks to slepnoga. > > ready to go stable? Yes, please stabilize sys-kernel/openvz-sources-2.6.32.85.17 on amd64 and x86 ASAP. After stabilization, please remove old ebuild. P.S Please add pva@ in CC.
Arches, please test and mark stable: =sys-kernel/openvz-sources-2.6.32.85.17 target KEYWORDS="amd64 x86"
*** Bug 501594 has been marked as a duplicate of this bug. ***
# make && make modules_install ... CC crypto/signature/ksign-publickey.o crypto/signature/ksign-publickey.c:2:17: fatal error: key.h: No such file or directory #include "key.h" ^ compilation terminated. scripts/Makefile.build:229: recipe for target 'crypto/signature/ksign-publickey.o' failed make[2]: *** [crypto/signature/ksign-publickey.o] Error 1 scripts/Makefile.build:365: recipe for target 'crypto/signature' failed make[1]: *** [crypto/signature] Error 2 Makefile:917: recipe for target 'crypto' failed make: *** [crypto] Error 2 This is after a "make oldconfig" from 2.6.32.84.26, using the settings suggested in upstreams conf file. Almost appears as if a file was missing?
(In reply to Joakim from comment #6) > # make && make modules_install > ... > CC crypto/signature/ksign-publickey.o > crypto/signature/ksign-publickey.c:2:17: fatal error: key.h: No such file or > directory > #include "key.h" > ^ > compilation terminated. > scripts/Makefile.build:229: recipe for target > 'crypto/signature/ksign-publickey.o' failed > make[2]: *** [crypto/signature/ksign-publickey.o] Error 1 > scripts/Makefile.build:365: recipe for target 'crypto/signature' failed > make[1]: *** [crypto/signature] Error 2 > Makefile:917: recipe for target 'crypto' failed > make: *** [crypto] Error 2 > > This is after a "make oldconfig" from 2.6.32.84.26, using the settings > suggested in upstreams conf file. Almost appears as if a file was missing? Please open a new bug.
(In reply to Joakim from comment #6) > # make && make modules_install > ... > CC crypto/signature/ksign-publickey.o > crypto/signature/ksign-publickey.c:2:17: fatal error: key.h: No such file or > directory > #include "key.h" > ^ > compilation terminated. > scripts/Makefile.build:229: recipe for target > 'crypto/signature/ksign-publickey.o' failed > make[2]: *** [crypto/signature/ksign-publickey.o] Error 1 > scripts/Makefile.build:365: recipe for target 'crypto/signature' failed > make[1]: *** [crypto/signature] Error 2 > Makefile:917: recipe for target 'crypto' failed > make: *** [crypto] Error 2 > > This is after a "make oldconfig" from 2.6.32.84.26, using the settings > suggested in upstreams conf file. Almost appears as if a file was missing? Yes, it's (openvz upstream) config bug. Please disable "module signing" feature. http://foxpa.ws/2012/08/27/ksign-publickey-c217-error-key-h-no-such-file-or-directory/
(In reply to Andreis Vinogradovs ( slepnoga ) from comment #3) > Yes, please stabilize sys-kernel/openvz-sources-2.6.32.85.17 on amd64 and > x86 ASAP. > After stabilization, please remove old ebuild. > > P.S Please add pva@ in CC. We do not have the proper environment to really test it. So if pva is not around to do it, we can just trust and commit.
amd64 stable
x86 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one.
unstable versions are cleared up, stable versions <sys-kernel/openvz-sources-2.6.32.85.17 are masked.
Cleanup was done, no GLSA for kernel packages. Thanks guys, closing