Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #229296 > unrolled thread

sad dns

Started bymj <lists@merit.unu.edu>
First post2020-12-04 12:40 +0100
Last post2020-12-07 15:00 +0100
Articles 6 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  sad dns mj <lists@merit.unu.edu> - 2020-12-04 12:40 +0100
    Re: sad dns Reco <recoverym4n@enotuniq.net> - 2020-12-04 13:10 +0100
    Re: sad dns Roberto C. Sánchez <roberto@debian.org> - 2020-12-04 16:00 +0100
      Re: sad dns mj <lists@merit.unu.edu> - 2020-12-07 08:50 +0100
        Re: sad dns Reco <recoverym4n@enotuniq.net> - 2020-12-07 09:10 +0100
          Re: sad dns mj <lists@merit.unu.edu> - 2020-12-07 15:00 +0100

#229296 — sad dns

Frommj <lists@merit.unu.edu>
Date2020-12-04 12:40 +0100
Subjectsad dns
Message-ID<BihBo-4GC-3@gated-at.bofh.it>
Hi,

I am wondering about the SAD DNS vulnerability, and wether or not it is 
solved in up-to-date debian 10.6.

https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way

It says, bottom of the page, that fixes are scheduled to in week 48 for 
debian and ubuntu.

However, I haven't seen any kernel updates.

Anyone with more information? (or pointers where to look for more 
debian-specific info)

Thanks!

MJ

[toc] | [next] | [standalone]


#229298

FromReco <recoverym4n@enotuniq.net>
Date2020-12-04 13:10 +0100
Message-ID<Bii4q-55P-5@gated-at.bofh.it>
In reply to#229296
	Hi.

On Fri, Dec 04, 2020 at 12:13:02PM +0100, mj wrote:
> I am wondering about the SAD DNS vulnerability, and wether or not it is solved in up-to-date debian 10.6.
> https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way
> It says, bottom of the page, that fixes are scheduled to in week 48 for debian and ubuntu.
> However, I haven't seen any kernel updates.
> Anyone with more information? (or pointers where to look for more debian-specific info)

CVE-2020-25705 was fixed in upstream kernel 4.19.153, and stable kind of got
this version (you have to know where to look for it):

linux (4.19.160-1) buster; urgency=medium
  * New upstream stable update:
    https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.153
    - icmp: randomize the global rate limiter (CVE-2020-25705)
...
 -- Salvatore Bonaccorso <carnil@debian.org>  Thu, 26 Nov 2020 21:23:20 +0100

Currently this kernel version sits in stable-proposed-updates.

Reco

[toc] | [prev] | [next] | [standalone]


#229309

FromRoberto C. Sánchez <roberto@debian.org>
Date2020-12-04 16:00 +0100
Message-ID<BikIV-6vM-5@gated-at.bofh.it>
In reply to#229296
On Fri, Dec 04, 2020 at 12:13:02PM +0100, mj wrote:
> Hi,
> 
> I am wondering about the SAD DNS vulnerability, and wether or not it is
> solved in up-to-date debian 10.6.
> 
> https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way
> 
> It says, bottom of the page, that fixes are scheduled to in week 48 for
> debian and ubuntu.
> 
> However, I haven't seen any kernel updates.
> 
> Anyone with more information? (or pointers where to look for more
> debian-specific info)
> 
The Debian Security Tracker shows the status of the associated CVE in
Debian:

https://security-tracker.debian.org/tracker/CVE-2020-25705

Essentially, the fix is in testing/unstable but has yet to reach stable
and oldstable.

Regards,

-Roberto

-- 
Roberto C. Sánchez

[toc] | [prev] | [next] | [standalone]


#229409

Frommj <lists@merit.unu.edu>
Date2020-12-07 08:50 +0100
Message-ID<Bjjrr-4ZB-5@gated-at.bofh.it>
In reply to#229309
Hi Roberto and Reco,

Thanks for the replies!

MJ

On 12/4/20 3:58 PM, Roberto C. Sánchez wrote:
> On Fri, Dec 04, 2020 at 12:13:02PM +0100, mj wrote:
>> Hi,
>>
>> I am wondering about the SAD DNS vulnerability, and wether or not it is
>> solved in up-to-date debian 10.6.
>>
>> https://blog.kernelcare.com/vulnerability/kernelcare-patches-for-sad-dns-are-on-the-way
>>
>> It says, bottom of the page, that fixes are scheduled to in week 48 for
>> debian and ubuntu.
>>
>> However, I haven't seen any kernel updates.
>>
>> Anyone with more information? (or pointers where to look for more
>> debian-specific info)
>>
> The Debian Security Tracker shows the status of the associated CVE in
> Debian:
> 
> https://security-tracker.debian.org/tracker/CVE-2020-25705
> 
> Essentially, the fix is in testing/unstable but has yet to reach stable
> and oldstable.
> 
> Regards,
> 
> -Roberto
> 

[toc] | [prev] | [next] | [standalone]


#229411

FromReco <recoverym4n@enotuniq.net>
Date2020-12-07 09:10 +0100
Message-ID<BjjKO-5lf-3@gated-at.bofh.it>
In reply to#229409
	Hi.

On Mon, Dec 07, 2020 at 08:31:27AM +0100, mj wrote:
> Hi Roberto and Reco,
> 
> Thanks for the replies!

A followup. They have released Debian 10.7 last weekend, kernel version
4.19.0-13 fixes this vulnerability.

Reco

[toc] | [prev] | [next] | [standalone]


#229413

Frommj <lists@merit.unu.edu>
Date2020-12-07 15:00 +0100
Message-ID<Bjpdw-g0-9@gated-at.bofh.it>
In reply to#229411
Hi

On 12/7/20 9:02 AM, Reco wrote:
> A followup. They have released Debian 10.7 last weekend, kernel version
> 4.19.0-13 fixes this vulnerability.

Yes, and we have installed it! :-)

Thanks again!

MJ

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web