Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #58955
| From | Julien Aubin <julien.aubin@gmail.com> |
|---|---|
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#875881: linux: CVE-2017-1000251 |
| Date | 2017-09-20 22:00 +0200 |
| Message-ID | <urTk5-7sy-7@gated-at.bofh.it> (permalink) |
| References | <uq06m-4g8-19@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Cross-posted to 2 groups.
[Multipart message — attachments visible in raw view] - view raw
On Sat, 16 Sep 2017 16:40:24 +0200 Julien Aubin <julien.aubin@gmail.com> wrote: > 2017-09-15 21:03 GMT+02:00 Christoph Anton Mitterer <calestyo@scientia.net >: > > > On Fri, 2017-09-15 at 19:18 +0100, Ben Hutchings wrote: > > > Probably less critical than you think, since we enable > > > CONFIG_CC_STACKPROTECTOR. > > > > Well... yes, but it wouldn't be the first time in history, that such > > defence could then also be circumvented in the next evolution of an > > exploit :-) > > > > But of course you can lower the bug severity if you think this is > > appropriate. > > > > Cheers&thx. > > > Looks like such issue has been found, stack clash is back : > https://security-tracker.debian.org/tracker/CVE-2017-1000379 Could you please backport the fix to stable ? Thanks !
Back to linux.debian.kernel | Previous | Next | Find similar | Unroll thread
Bug#875881: linux: CVE-2017-1000251 Julien Aubin <julien.aubin@gmail.com> - 2017-09-20 22:00 +0200
csiph-web