Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #246079 > unrolled thread

dirty-pipe

Started bygene heskett <gheskett@shentel.net>
First post2022-03-08 21:40 +0100
Last post2022-03-08 22:20 +0100
Articles 7 — 5 participants

Back to article view | Back to linux.debian.user


Contents

  dirty-pipe gene heskett <gheskett@shentel.net> - 2022-03-08 21:40 +0100
    Re: dirty-pipe <tomas@tuxteam.de> - 2022-03-08 22:00 +0100
      Re: dirty-pipe tomas@tuxteam.de - 2022-03-08 22:10 +0100
        Re: dirty-pipe gene heskett <gheskett@shentel.net> - 2022-03-08 22:30 +0100
      Re: dirty-pipe gene heskett <gheskett@shentel.net> - 2022-03-08 22:30 +0100
      Re: dirty-pipe Stefan Monnier <monnier@iro.umontreal.ca> - 2022-03-08 22:50 +0100
    Re: dirty-pipe Dan Ritter <dsr@randomstring.org> - 2022-03-08 22:20 +0100

#246079 — dirty-pipe

Fromgene heskett <gheskett@shentel.net>
Date2022-03-08 21:40 +0100
Subjectdirty-pipe
Message-ID<DYOMF-qG9-1@gated-at.bofh.it>
Grettings all;

Am I to assume that the kernel synaptic is installiing right now fixes 
dirty-pipe?

Cheers, Gene Heskett.
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis

[toc] | [next] | [standalone]


#246081

From<tomas@tuxteam.de>
Date2022-03-08 22:00 +0100
Message-ID<DYP61-qME-1@gated-at.bofh.it>
In reply to#246079

[Multipart message — attachments visible in raw view] — view raw

On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote:
> Grettings all;
> 
> Am I to assume that the kernel synaptic is installiing right now fixes 
> dirty-pipe?

  "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102." [1]

[1] https://lwn.net/Articles/887056/

-- 
t

[toc] | [prev] | [next] | [standalone]


#246083

Fromtomas@tuxteam.de
Date2022-03-08 22:10 +0100
Message-ID<DYPfH-r5h-1@gated-at.bofh.it>
In reply to#246081

[Multipart message — attachments visible in raw view] — view raw

On Tue, Mar 08, 2022 at 09:54:43PM +0100, tomas@tuxteam.de wrote:
> On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote:
> > Grettings all;
> > 
> > Am I to assume that the kernel synaptic is installiing right now fixes 
> > dirty-pipe?
> 
>   "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102." [1]
> 
> [1] https://lwn.net/Articles/887056/

Replying to self: ah, but this is CVE-2022-0847. According to [2], it is
fixed in current stable with kernel package 5.10.92-2. So yes.

[2] https://www.debian.org/security/2022/dsa-5092
-- 
t

[toc] | [prev] | [next] | [standalone]


#246089

Fromgene heskett <gheskett@shentel.net>
Date2022-03-08 22:30 +0100
Message-ID<DYPz3-rc3-15@gated-at.bofh.it>
In reply to#246083
On Tuesday, 8 March 2022 16:06:54 EST tomas@tuxteam.de wrote:
> On Tue, Mar 08, 2022 at 09:54:43PM +0100, tomas@tuxteam.de wrote:
> > On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote:
> > > Grettings all;
> > > 
> > > Am I to assume that the kernel synaptic is installiing right now
> > > fixes
> > > dirty-pipe?
> > > 
> >   "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and
> >   5.10.102." [1]> 
> > [1] https://lwn.net/Articles/887056/
> 
> Replying to self: ah, but this is CVE-2022-0847. According to [2], it
> is fixed in current stable with kernel package 5.10.92-2. So yes.
> 
> [2] https://www.debian.org/security/2022/dsa-5092
> --
> t
Thank you Tomas.  Heads up folks, update and reboot. Now if not sooner.

Cheers, Gene Heskett.
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis

[toc] | [prev] | [next] | [standalone]


#246087

Fromgene heskett <gheskett@shentel.net>
Date2022-03-08 22:30 +0100
Message-ID<DYPz3-rc3-1@gated-at.bofh.it>
In reply to#246081
On Tuesday, 8 March 2022 15:54:43 EST tomas@tuxteam.de wrote:
> On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote:
> > Grettings all;
> > 
> > Am I to assume that the kernel synaptic is installiing right now
> > fixes
> > dirty-pipe?
> 
>   "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102."
> [1]

Ack uname, the image it just installed and I rebooted to is older, but 
the changelog does mention a new_pipe flag fix? So I'm confused.

gene@coyote:~$ uname -a
Linux coyote 5.10.0-11-amd64 #1 SMP Debian 5.10.92-2 (2022-02-28) x86_64 
GNU/Linux
> [1] https://lwn.net/Articles/887056/
> 
> --
> t


Cheers, Gene Heskett.
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
 - Louis D. Brandeis

[toc] | [prev] | [next] | [standalone]


#246090

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2022-03-08 22:50 +0100
Message-ID<DYPSp-riq-9@gated-at.bofh.it>
In reply to#246081
tomas@tuxteam.de [2022-03-08 21:54:43] wrote:
> On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote:
>> Grettings all;
>> Am I to assume that the kernel synaptic is installiing right now fixes 
>> dirty-pipe?
>   "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102." [1]
> [1] https://lwn.net/Articles/887056/

And for Debian, the details can be found:

    https://security-tracker.debian.org/tracker/CVE-2022-0847


-- Stefan

[toc] | [prev] | [next] | [standalone]


#246086

FromDan Ritter <dsr@randomstring.org>
Date2022-03-08 22:20 +0100
Message-ID<DYPpn-r8P-3@gated-at.bofh.it>
In reply to#246079
gene heskett wrote: 
> Grettings all;
> 
> Am I to assume that the kernel synaptic is installiing right now fixes 
> dirty-pipe?

Yes, assuming that you're getting a linux kernel update for
Bullseye today.

Package        : linux
CVE ID         : CVE-2021-43976 CVE-2022-0330 CVE-2022-0435
CVE-2022-0516
                 CVE-2022-0847 CVE-2022-22942 CVE-2022-24448
CVE-2022-24959
                 CVE-2022-25258 CVE-2022-25375


2022-0847 is called "Dirty Pipe".

https://dirtypipe.cm4all.com/

-dsr-

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web