Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #229296 > unrolled thread
| Started by | mj <lists@merit.unu.edu> |
|---|---|
| First post | 2020-12-04 12:40 +0100 |
| Last post | 2020-12-07 15:00 +0100 |
| Articles | 6 — 3 participants |
Back to article view | Back to linux.debian.user
sad dns mj <lists@merit.unu.edu> - 2020-12-04 12:40 +0100
Re: sad dns Reco <recoverym4n@enotuniq.net> - 2020-12-04 13:10 +0100
Re: sad dns Roberto C. Sánchez <roberto@debian.org> - 2020-12-04 16:00 +0100
Re: sad dns mj <lists@merit.unu.edu> - 2020-12-07 08:50 +0100
Re: sad dns Reco <recoverym4n@enotuniq.net> - 2020-12-07 09:10 +0100
Re: sad dns mj <lists@merit.unu.edu> - 2020-12-07 15:00 +0100
| From | mj <lists@merit.unu.edu> |
|---|---|
| Date | 2020-12-04 12:40 +0100 |
| Subject | sad dns |
| Message-ID | <BihBo-4GC-3@gated-at.bofh.it> |
Hi, I am wondering about the SAD DNS vulnerability, and wether or not it is solved in up-to-date debian 10.6. https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way It says, bottom of the page, that fixes are scheduled to in week 48 for debian and ubuntu. However, I haven't seen any kernel updates. Anyone with more information? (or pointers where to look for more debian-specific info) Thanks! MJ
[toc] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2020-12-04 13:10 +0100 |
| Message-ID | <Bii4q-55P-5@gated-at.bofh.it> |
| In reply to | #229296 |
Hi.
On Fri, Dec 04, 2020 at 12:13:02PM +0100, mj wrote:
> I am wondering about the SAD DNS vulnerability, and wether or not it is solved in up-to-date debian 10.6.
> https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way
> It says, bottom of the page, that fixes are scheduled to in week 48 for debian and ubuntu.
> However, I haven't seen any kernel updates.
> Anyone with more information? (or pointers where to look for more debian-specific info)
CVE-2020-25705 was fixed in upstream kernel 4.19.153, and stable kind of got
this version (you have to know where to look for it):
linux (4.19.160-1) buster; urgency=medium
* New upstream stable update:
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.153
- icmp: randomize the global rate limiter (CVE-2020-25705)
...
-- Salvatore Bonaccorso <carnil@debian.org> Thu, 26 Nov 2020 21:23:20 +0100
Currently this kernel version sits in stable-proposed-updates.
Reco
[toc] | [prev] | [next] | [standalone]
| From | Roberto C. Sánchez <roberto@debian.org> |
|---|---|
| Date | 2020-12-04 16:00 +0100 |
| Message-ID | <BikIV-6vM-5@gated-at.bofh.it> |
| In reply to | #229296 |
On Fri, Dec 04, 2020 at 12:13:02PM +0100, mj wrote: > Hi, > > I am wondering about the SAD DNS vulnerability, and wether or not it is > solved in up-to-date debian 10.6. > > https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way > > It says, bottom of the page, that fixes are scheduled to in week 48 for > debian and ubuntu. > > However, I haven't seen any kernel updates. > > Anyone with more information? (or pointers where to look for more > debian-specific info) > The Debian Security Tracker shows the status of the associated CVE in Debian: https://security-tracker.debian.org/tracker/CVE-2020-25705 Essentially, the fix is in testing/unstable but has yet to reach stable and oldstable. Regards, -Roberto -- Roberto C. Sánchez
[toc] | [prev] | [next] | [standalone]
| From | mj <lists@merit.unu.edu> |
|---|---|
| Date | 2020-12-07 08:50 +0100 |
| Message-ID | <Bjjrr-4ZB-5@gated-at.bofh.it> |
| In reply to | #229309 |
Hi Roberto and Reco, Thanks for the replies! MJ On 12/4/20 3:58 PM, Roberto C. Sánchez wrote: > On Fri, Dec 04, 2020 at 12:13:02PM +0100, mj wrote: >> Hi, >> >> I am wondering about the SAD DNS vulnerability, and wether or not it is >> solved in up-to-date debian 10.6. >> >> https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way >> >> It says, bottom of the page, that fixes are scheduled to in week 48 for >> debian and ubuntu. >> >> However, I haven't seen any kernel updates. >> >> Anyone with more information? (or pointers where to look for more >> debian-specific info) >> > The Debian Security Tracker shows the status of the associated CVE in > Debian: > > https://security-tracker.debian.org/tracker/CVE-2020-25705 > > Essentially, the fix is in testing/unstable but has yet to reach stable > and oldstable. > > Regards, > > -Roberto >
[toc] | [prev] | [next] | [standalone]
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Date | 2020-12-07 09:10 +0100 |
| Message-ID | <BjjKO-5lf-3@gated-at.bofh.it> |
| In reply to | #229409 |
Hi. On Mon, Dec 07, 2020 at 08:31:27AM +0100, mj wrote: > Hi Roberto and Reco, > > Thanks for the replies! A followup. They have released Debian 10.7 last weekend, kernel version 4.19.0-13 fixes this vulnerability. Reco
[toc] | [prev] | [next] | [standalone]
| From | mj <lists@merit.unu.edu> |
|---|---|
| Date | 2020-12-07 15:00 +0100 |
| Message-ID | <Bjpdw-g0-9@gated-at.bofh.it> |
| In reply to | #229411 |
Hi On 12/7/20 9:02 AM, Reco wrote: > A followup. They have released Debian 10.7 last weekend, kernel version > 4.19.0-13 fixes this vulnerability. Yes, and we have installed it! :-) Thanks again! MJ
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web