Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #229298

Re: sad dns

From Reco <recoverym4n@enotuniq.net>
Newsgroups linux.debian.user
Subject Re: sad dns
Date 2020-12-04 13:10 +0100
Message-ID <Bii4q-55P-5@gated-at.bofh.it> (permalink)
References <BihBo-4GC-3@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


	Hi.

On Fri, Dec 04, 2020 at 12:13:02PM +0100, mj wrote:
> I am wondering about the SAD DNS vulnerability, and wether or not it is solved in up-to-date debian 10.6.
> https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way
> It says, bottom of the page, that fixes are scheduled to in week 48 for debian and ubuntu.
> However, I haven't seen any kernel updates.
> Anyone with more information? (or pointers where to look for more debian-specific info)

CVE-2020-25705 was fixed in upstream kernel 4.19.153, and stable kind of got
this version (you have to know where to look for it):

linux (4.19.160-1) buster; urgency=medium
  * New upstream stable update:
    https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.153
    - icmp: randomize the global rate limiter (CVE-2020-25705)
...
 -- Salvatore Bonaccorso <carnil@debian.org>  Thu, 26 Nov 2020 21:23:20 +0100

Currently this kernel version sits in stable-proposed-updates.

Reco

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

sad dns mj <lists@merit.unu.edu> - 2020-12-04 12:40 +0100
  Re: sad dns Reco <recoverym4n@enotuniq.net> - 2020-12-04 13:10 +0100
  Re: sad dns Roberto C. Sánchez <roberto@debian.org> - 2020-12-04 16:00 +0100
    Re: sad dns mj <lists@merit.unu.edu> - 2020-12-07 08:50 +0100
      Re: sad dns Reco <recoverym4n@enotuniq.net> - 2020-12-07 09:10 +0100
        Re: sad dns mj <lists@merit.unu.edu> - 2020-12-07 15:00 +0100

csiph-web