Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #72317 > unrolled thread
| Started by | Michael Biebl <biebl@debian.org> |
|---|---|
| First post | 2021-06-28 15:50 +0200 |
| Last post | 2021-07-06 15:10 +0200 |
| Articles | 6 — 4 participants |
Back to article view | Back to linux.debian.kernel
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 Michael Biebl <biebl@debian.org> - 2021-06-28 15:50 +0200
Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 Tomas Pospisek <tpo_deb@sourcepole.ch> - 2021-06-30 21:30 +0200
Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 Michael Biebl <biebl@debian.org> - 2021-06-30 21:40 +0200
Processed: Re: Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2021-06-30 22:00 +0200
Processed (with 5 errors): Re: Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 "Debian Bug Tracking System" <owner@bugs.debian.org> - 2021-06-30 21:40 +0200
Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 Moritz Mühlenhoff <jmm@inutil.org> - 2021-07-06 15:10 +0200
| From | Michael Biebl <biebl@debian.org> |
|---|---|
| Date | 2021-06-28 15:50 +0200 |
| Subject | Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 |
| Message-ID | <CuZOa-WF-3@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Am 28.06.21 um 14:52 schrieb Tomas Pospisek: > Package: systemd > Version: 247.3-5 > Severity: wishlist > Tags: security > X-Debbugs-Cc: Debian Security Team <team@security.debian.org> > > Hi, > > TLDR: > > $ sudo sysctl kernel.unprivileged_bpf_disabled > kernel.unprivileged_bpf_disabled = 0 > > please disable unprivileged BPF by default, it seems that it > is not safe to be allowed by default in the general case. > > I'm not sure if systemd is the right place to report this > security/wishlist ticket against. I've chosen systemd because it > ships `/etc/sysctl.d/99-sysctl.conf` which seems to me to be the > nearest fit to where `kernel.unprivileged_bpf_disabled` should > be set. Please reassign if there's a better package to stick > this report to. /etc/sysctl.d/99-sysctl.conf is just a symlink pointing at 99-sysctl.conf -> ../sysctl.conf $ dpkg -S /etc/sysctl.conf procps: /etc/sysctl.conf tbh, I'd prefer the security oder kernel team to make that judgement call.
[toc] | [next] | [standalone]
| From | Tomas Pospisek <tpo_deb@sourcepole.ch> |
|---|---|
| Date | 2021-06-30 21:30 +0200 |
| Message-ID | <CvO4i-5SU-1@gated-at.bofh.it> |
| In reply to | #72317 |
reassign 990411 linux-image-5.10.0-7-amd64 ----- Thanks Michael, reassigning as proposed. Though I'm wondering (and not finding) whether there would be a more general package to assign this ticket to (such as linux-image-5.x or something). Any thoughts on this problem in the security or the kernel team? Thanks and greets to all of you! *t On Mon, 28 Jun 2021, Michael Biebl wrote: > Am 28.06.21 um 14:52 schrieb Tomas Pospisek: >> Package: systemd >> Version: 247.3-5 >> Severity: wishlist >> Tags: security >> X-Debbugs-Cc: Debian Security Team <team@security.debian.org> >> >> Hi, >> >> TLDR: >> >> $ sudo sysctl kernel.unprivileged_bpf_disabled >> kernel.unprivileged_bpf_disabled = 0 >> >> please disable unprivileged BPF by default, it seems that it >> is not safe to be allowed by default in the general case. >> >> I'm not sure if systemd is the right place to report this >> security/wishlist ticket against. I've chosen systemd because it >> ships `/etc/sysctl.d/99-sysctl.conf` which seems to me to be the >> nearest fit to where `kernel.unprivileged_bpf_disabled` should >> be set. Please reassign if there's a better package to stick >> this report to. > > /etc/sysctl.d/99-sysctl.conf is just a symlink pointing at > 99-sysctl.conf -> ../sysctl.conf > > $ dpkg -S /etc/sysctl.conf > procps: /etc/sysctl.conf > > tbh, I'd prefer the security oder kernel team to make that judgement call.
[toc] | [prev] | [next] | [standalone]
| From | Michael Biebl <biebl@debian.org> |
|---|---|
| Date | 2021-06-30 21:40 +0200 |
| Message-ID | <CvOdX-5W5-1@gated-at.bofh.it> |
| In reply to | #72327 |
[Multipart message — attachments visible in raw view] — view raw
Control: reassign -1 src:linux Am 30.06.21 um 20:33 schrieb Tomas Pospisek: > reassign 990411 linux-image-5.10.0-7-amd64 > > ----- > > Thanks Michael, reassigning as proposed. Though I'm wondering (and not > finding) whether there would be a more general package to assign this > ticket to (such as linux-image-5.x or something). > The kernel team afair prefers this to be assigned to src:linux.
[toc] | [prev] | [next] | [standalone]
| From | "Debian Bug Tracking System" <owner@bugs.debian.org> |
|---|---|
| Date | 2021-06-30 22:00 +0200 |
| Subject | Processed: Re: Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 |
| Message-ID | <CvOxj-62k-11@gated-at.bofh.it> |
| In reply to | #72328 |
Processing control commands: > reassign -1 src:linux Bug #990411 [linux-image-5.10.0-7-amd64] systemd: set kernel.unprivileged_bpf_disabled = 1 Bug reassigned from package 'linux-image-5.10.0-7-amd64' to 'src:linux'. Ignoring request to alter found versions of bug #990411 to the same values previously set Ignoring request to alter fixed versions of bug #990411 to the same values previously set -- 990411: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=990411 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
[toc] | [prev] | [next] | [standalone]
| From | "Debian Bug Tracking System" <owner@bugs.debian.org> |
|---|---|
| Date | 2021-06-30 21:40 +0200 |
| Subject | Processed (with 5 errors): Re: Bug#990411: systemd: set kernel.unprivileged_bpf_disabled = 1 |
| Message-ID | <CvOdY-5W5-11@gated-at.bofh.it> |
| In reply to | #72327 |
Processing commands for control@bugs.debian.org: > reassign 990411 linux-image-5.10.0-7-amd64 Bug #990411 [systemd] systemd: set kernel.unprivileged_bpf_disabled = 1 Bug reassigned from package 'systemd' to 'linux-image-5.10.0-7-amd64'. No longer marked as found in versions systemd/247.3-5. Ignoring request to alter fixed versions of bug #990411 to the same values previously set > ----- Unknown command or malformed arguments to command. > Thanks Michael, reassigning as proposed. Though I'm wondering (and not Unknown command or malformed arguments to command. > finding) whether there would be a more general package to assign this Unknown command or malformed arguments to command. > ticket to (such as linux-image-5.x or something). Unknown command or malformed arguments to command. > Any thoughts on this problem in the security or the kernel team? Unknown command or malformed arguments to command. Too many unknown commands, stopping here. Please contact me if you need assistance. -- 990411: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=990411 Debian Bug Tracking System Contact owner@bugs.debian.org with problems
[toc] | [prev] | [next] | [standalone]
| From | Moritz Mühlenhoff <jmm@inutil.org> |
|---|---|
| Date | 2021-07-06 15:10 +0200 |
| Message-ID | <CxSZP-52s-3@gated-at.bofh.it> |
| In reply to | #72327 |
Am Wed, Jun 30, 2021 at 08:33:01PM +0200 schrieb Tomas Pospisek:
> reassign 990411 linux-image-5.10.0-7-amd64
>
> -----
>
> Thanks Michael, reassigning as proposed. Though I'm wondering (and not
> finding) whether there would be a more general package to assign this ticket
> to (such as linux-image-5.x or something).
>
> Any thoughts on this problem in the security or the kernel team?
I agree it makes sense to disable it by default, but the ultimate
decision is up to the kernel team
Cheers,
Moritz
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web