Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #813976 > unrolled thread

Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch

Started byJulien Aubin <julien.aubin@gmail.com>
First post2017-03-18 17:10 +0100
Last post2017-04-06 07:10 +0200
Articles 6 — 3 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Julien Aubin <julien.aubin@gmail.com> - 2017-03-18 17:10 +0100
    Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Salvatore Bonaccorso <carnil@debian.org> - 2017-03-18 17:20 +0100
    Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Ben Hutchings <ben@decadent.org.uk> - 2017-03-18 22:00 +0100
      Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Julien Aubin <julien.aubin@gmail.com> - 2017-03-18 22:20 +0100
        Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Julien Aubin <julien.aubin@gmail.com> - 2017-03-19 10:50 +0100
    Bug#858122: closed by Salvatore Bonaccorso <carnil@debian.org> (Bug#858122: fixed in linux 4.9.16-1) Salvatore Bonaccorso <carnil@debian.org> - 2017-04-06 07:10 +0200

#813976 — Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch

FromJulien Aubin <julien.aubin@gmail.com>
Date2017-03-18 17:10 +0100
SubjectBug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch
Message-ID<tmp5v-pH-9@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Source: linux
Severity: critical
Tags: security
Justification: root security hole

Hi,

Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the fix
has
been provided for Jessie and Wheezy. The problem is that there's as of now
no
fix available for sid and stretch while things become more and more critical
due to the severity of the issue.

Kernel 4.9.15 contains a fix for this. Could you please integrate it ASAP on
Stretch ?

Thanks in advance.

More info at :
https://www.ptsecurity.com/ww-en/about/news/199636/



-- System Information:
Debian Release: 9.0
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-2-amd64 (SMP w/8 CPU cores)
Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

[toc] | [next] | [standalone]


#813978

FromSalvatore Bonaccorso <carnil@debian.org>
Date2017-03-18 17:20 +0100
Message-ID<tmpfb-sU-5@gated-at.bofh.it>
In reply to#813976
Hi

On Sat, Mar 18, 2017 at 05:01:56PM +0100, Julien Aubin wrote:
> Source: linux
> Severity: critical
> Tags: security
> Justification: root security hole
> 
> Hi,
> 
> Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the fix
> has
> been provided for Jessie and Wheezy. The problem is that there's as of now
> no
> fix available for sid and stretch while things become more and more critical
> due to the severity of the issue.
> 
> Kernel 4.9.15 contains a fix for this. Could you please integrate it ASAP on
> Stretch ?
> 
> Thanks in advance.

yes this is already pending in git.

https://anonscm.debian.org/cgit/kernel/linux.git/commit/?h=sid&id=11d69f4069a047f1fa0dffa71762b54fdde4f08f

Regards,
Salvatore

[toc] | [prev] | [next] | [standalone]


#814015

FromBen Hutchings <ben@decadent.org.uk>
Date2017-03-18 22:00 +0100
Message-ID<tmtC9-3rv-1@gated-at.bofh.it>
In reply to#813976

[Multipart message — attachments visible in raw view] — view raw

On Sat, 2017-03-18 at 17:01 +0100, Julien Aubin wrote:
> Source: linux
> Severity: critical
> Tags: security
> Justification: root security hole
> 
> Hi,
> 
> Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the fix
> has
> been provided for Jessie and Wheezy. The problem is that there's as of now
> no
> fix available for sid and stretch while things become more and more critical
> due to the severity of the issue.
> 
> Kernel 4.9.15 contains a fix for this. Could you please integrate it ASAP on
> Stretch ?
[...]

Note that we already documented a mitigation for this in the DSA.

Ben.

-- 
Ben Hutchings
Editing code like this is akin to sticking plasters on the bleeding
stump
of a severed limb. - me, 29 June 1999

[toc] | [prev] | [next] | [standalone]


#814021

FromJulien Aubin <julien.aubin@gmail.com>
Date2017-03-18 22:20 +0100
Message-ID<tmtVv-3Pb-15@gated-at.bofh.it>
In reply to#814015

[Multipart message — attachments visible in raw view] — view raw

OK I did this. Does it have a huge impact on the system except mitigating
the flaw ? (I don't think I have an HDLC hardware...)

2017-03-18 21:54 GMT+01:00 Ben Hutchings <ben@decadent.org.uk>:

> On Sat, 2017-03-18 at 17:01 +0100, Julien Aubin wrote:
> > Source: linux
> > Severity: critical
> > Tags: security
> > Justification: root security hole
> >
> > Hi,
> >
> > Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the
> fix
> > has
> > been provided for Jessie and Wheezy. The problem is that there's as of
> now
> > no
> > fix available for sid and stretch while things become more and more
> critical
> > due to the severity of the issue.
> >
> > Kernel 4.9.15 contains a fix for this. Could you please integrate it
> ASAP on
> > Stretch ?
> [...]
>
> Note that we already documented a mitigation for this in the DSA.
>
> Ben.
>
> --
> Ben Hutchings
> Editing code like this is akin to sticking plasters on the bleeding
> stump
> of a severed limb. - me, 29 June 1999
>
>

[toc] | [prev] | [next] | [standalone]


#814068

FromJulien Aubin <julien.aubin@gmail.com>
Date2017-03-19 10:50 +0100
Message-ID<tmFDj-3FE-1@gated-at.bofh.it>
In reply to#814021

[Multipart message — attachments visible in raw view] — view raw

Yup checked. These drivers are used for satellite communication devices.
Unsure many desktop and server users need them.

Le 18 mars 2017 23:01, "Ben Hutchings" <ben@decadent.org.uk> a écrit :

> On Sat, Mar 18, 2017 at 10:08:10PM +0100, Julien Aubin wrote:
> > OK I did this. Does it have a huge impact on the system except mitigating
> > the flaw ? (I don't think I have an HDLC hardware...)
>
> If you don't know whether you have it, you don't have it. :-)
>
> Ben.
>
> --
> Ben Hutchings
> Life is like a sewer:
> what you get out of it depends on what you put into it.
>

[toc] | [prev] | [next] | [standalone]


#817434 — Bug#858122: closed by Salvatore Bonaccorso <carnil@debian.org> (Bug#858122: fixed in linux 4.9.16-1)

FromSalvatore Bonaccorso <carnil@debian.org>
Date2017-04-06 07:10 +0200
SubjectBug#858122: closed by Salvatore Bonaccorso <carnil@debian.org> (Bug#858122: fixed in linux 4.9.16-1)
Message-ID<tt7Qd-494-1@gated-at.bofh.it>
In reply to#813976
Hi Julien,

On Mon, Apr 03, 2017 at 09:00:27PM +0200, Julien Aubin wrote:
> Hi Salvatore,
> 
> Regarding this issue which is critical, could you please unblock the
> migration to testing of the 4.9.18 kernel ?

It's not something I can do, but release manager have done so (now),
and the time to migrate will be as well speed up a bit.

Regards,
Salvatore

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web