Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #57270 > unrolled thread
| Started by | Julien Aubin <julien.aubin@gmail.com> |
|---|---|
| First post | 2017-03-18 17:10 +0100 |
| Last post | 2017-04-06 07:10 +0200 |
| Articles | 6 — 3 participants |
Back to article view | Back to linux.debian.kernel
Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Julien Aubin <julien.aubin@gmail.com> - 2017-03-18 17:10 +0100
Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Salvatore Bonaccorso <carnil@debian.org> - 2017-03-18 17:20 +0100
Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Ben Hutchings <ben@decadent.org.uk> - 2017-03-18 22:00 +0100
Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Julien Aubin <julien.aubin@gmail.com> - 2017-03-18 22:20 +0100
Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch Julien Aubin <julien.aubin@gmail.com> - 2017-03-19 10:50 +0100
Bug#858122: closed by Salvatore Bonaccorso <carnil@debian.org> (Bug#858122: fixed in linux 4.9.16-1) Salvatore Bonaccorso <carnil@debian.org> - 2017-04-06 07:10 +0200
| From | Julien Aubin <julien.aubin@gmail.com> |
|---|---|
| Date | 2017-03-18 17:10 +0100 |
| Subject | Bug#858122: Upgrade linux kernel to 4.9.15 in sid and stretch |
| Message-ID | <tmp5v-pH-9@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Source: linux Severity: critical Tags: security Justification: root security hole Hi, Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the fix has been provided for Jessie and Wheezy. The problem is that there's as of now no fix available for sid and stretch while things become more and more critical due to the severity of the issue. Kernel 4.9.15 contains a fix for this. Could you please integrate it ASAP on Stretch ? Thanks in advance. More info at : https://www.ptsecurity.com/ww-en/about/news/199636/ -- System Information: Debian Release: 9.0 APT prefers testing APT policy: (500, 'testing') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 4.9.0-2-amd64 (SMP w/8 CPU cores) Locale: LANG=fr_FR.UTF-8, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system)
[toc] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2017-03-18 17:20 +0100 |
| Message-ID | <tmpfb-sU-5@gated-at.bofh.it> |
| In reply to | #57270 |
Hi On Sat, Mar 18, 2017 at 05:01:56PM +0100, Julien Aubin wrote: > Source: linux > Severity: critical > Tags: security > Justification: root security hole > > Hi, > > Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the fix > has > been provided for Jessie and Wheezy. The problem is that there's as of now > no > fix available for sid and stretch while things become more and more critical > due to the severity of the issue. > > Kernel 4.9.15 contains a fix for this. Could you please integrate it ASAP on > Stretch ? > > Thanks in advance. yes this is already pending in git. https://anonscm.debian.org/cgit/kernel/linux.git/commit/?h=sid&id=11d69f4069a047f1fa0dffa71762b54fdde4f08f Regards, Salvatore
[toc] | [prev] | [next] | [standalone]
| From | Ben Hutchings <ben@decadent.org.uk> |
|---|---|
| Date | 2017-03-18 22:00 +0100 |
| Message-ID | <tmtC9-3rv-1@gated-at.bofh.it> |
| In reply to | #57270 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, 2017-03-18 at 17:01 +0100, Julien Aubin wrote: > Source: linux > Severity: critical > Tags: security > Justification: root security hole > > Hi, > > Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the fix > has > been provided for Jessie and Wheezy. The problem is that there's as of now > no > fix available for sid and stretch while things become more and more critical > due to the severity of the issue. > > Kernel 4.9.15 contains a fix for this. Could you please integrate it ASAP on > Stretch ? [...] Note that we already documented a mitigation for this in the DSA. Ben. -- Ben Hutchings Editing code like this is akin to sticking plasters on the bleeding stump of a severed limb. - me, 29 June 1999
[toc] | [prev] | [next] | [standalone]
| From | Julien Aubin <julien.aubin@gmail.com> |
|---|---|
| Date | 2017-03-18 22:20 +0100 |
| Message-ID | <tmtVv-3Pb-15@gated-at.bofh.it> |
| In reply to | #57274 |
[Multipart message — attachments visible in raw view] — view raw
OK I did this. Does it have a huge impact on the system except mitigating the flaw ? (I don't think I have an HDLC hardware...) 2017-03-18 21:54 GMT+01:00 Ben Hutchings <ben@decadent.org.uk>: > On Sat, 2017-03-18 at 17:01 +0100, Julien Aubin wrote: > > Source: linux > > Severity: critical > > Tags: security > > Justification: root security hole > > > > Hi, > > > > Security issue CVE-2017-2636 (severity 7.8) has been disclosed and the > fix > > has > > been provided for Jessie and Wheezy. The problem is that there's as of > now > > no > > fix available for sid and stretch while things become more and more > critical > > due to the severity of the issue. > > > > Kernel 4.9.15 contains a fix for this. Could you please integrate it > ASAP on > > Stretch ? > [...] > > Note that we already documented a mitigation for this in the DSA. > > Ben. > > -- > Ben Hutchings > Editing code like this is akin to sticking plasters on the bleeding > stump > of a severed limb. - me, 29 June 1999 > >
[toc] | [prev] | [next] | [standalone]
| From | Julien Aubin <julien.aubin@gmail.com> |
|---|---|
| Date | 2017-03-19 10:50 +0100 |
| Message-ID | <tmFDj-3FE-1@gated-at.bofh.it> |
| In reply to | #57277 |
[Multipart message — attachments visible in raw view] — view raw
Yup checked. These drivers are used for satellite communication devices. Unsure many desktop and server users need them. Le 18 mars 2017 23:01, "Ben Hutchings" <ben@decadent.org.uk> a écrit : > On Sat, Mar 18, 2017 at 10:08:10PM +0100, Julien Aubin wrote: > > OK I did this. Does it have a huge impact on the system except mitigating > > the flaw ? (I don't think I have an HDLC hardware...) > > If you don't know whether you have it, you don't have it. :-) > > Ben. > > -- > Ben Hutchings > Life is like a sewer: > what you get out of it depends on what you put into it. >
[toc] | [prev] | [next] | [standalone]
| From | Salvatore Bonaccorso <carnil@debian.org> |
|---|---|
| Date | 2017-04-06 07:10 +0200 |
| Subject | Bug#858122: closed by Salvatore Bonaccorso <carnil@debian.org> (Bug#858122: fixed in linux 4.9.16-1) |
| Message-ID | <tt7Qd-494-1@gated-at.bofh.it> |
| In reply to | #57270 |
Hi Julien, On Mon, Apr 03, 2017 at 09:00:27PM +0200, Julien Aubin wrote: > Hi Salvatore, > > Regarding this issue which is critical, could you please unblock the > migration to testing of the 4.9.18 kernel ? It's not something I can do, but release manager have done so (now), and the time to migrate will be as well speed up a bit. Regards, Salvatore
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.kernel
csiph-web