Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #246079 > unrolled thread
| Started by | gene heskett <gheskett@shentel.net> |
|---|---|
| First post | 2022-03-08 21:40 +0100 |
| Last post | 2022-03-08 22:20 +0100 |
| Articles | 7 — 5 participants |
Back to article view | Back to linux.debian.user
dirty-pipe gene heskett <gheskett@shentel.net> - 2022-03-08 21:40 +0100
Re: dirty-pipe <tomas@tuxteam.de> - 2022-03-08 22:00 +0100
Re: dirty-pipe tomas@tuxteam.de - 2022-03-08 22:10 +0100
Re: dirty-pipe gene heskett <gheskett@shentel.net> - 2022-03-08 22:30 +0100
Re: dirty-pipe gene heskett <gheskett@shentel.net> - 2022-03-08 22:30 +0100
Re: dirty-pipe Stefan Monnier <monnier@iro.umontreal.ca> - 2022-03-08 22:50 +0100
Re: dirty-pipe Dan Ritter <dsr@randomstring.org> - 2022-03-08 22:20 +0100
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2022-03-08 21:40 +0100 |
| Subject | dirty-pipe |
| Message-ID | <DYOMF-qG9-1@gated-at.bofh.it> |
Grettings all; Am I to assume that the kernel synaptic is installiing right now fixes dirty-pipe? Cheers, Gene Heskett. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-03-08 22:00 +0100 |
| Message-ID | <DYP61-qME-1@gated-at.bofh.it> |
| In reply to | #246079 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote: > Grettings all; > > Am I to assume that the kernel synaptic is installiing right now fixes > dirty-pipe? "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102." [1] [1] https://lwn.net/Articles/887056/ -- t
[toc] | [prev] | [next] | [standalone]
| From | tomas@tuxteam.de |
|---|---|
| Date | 2022-03-08 22:10 +0100 |
| Message-ID | <DYPfH-r5h-1@gated-at.bofh.it> |
| In reply to | #246081 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Mar 08, 2022 at 09:54:43PM +0100, tomas@tuxteam.de wrote: > On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote: > > Grettings all; > > > > Am I to assume that the kernel synaptic is installiing right now fixes > > dirty-pipe? > > "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102." [1] > > [1] https://lwn.net/Articles/887056/ Replying to self: ah, but this is CVE-2022-0847. According to [2], it is fixed in current stable with kernel package 5.10.92-2. So yes. [2] https://www.debian.org/security/2022/dsa-5092 -- t
[toc] | [prev] | [next] | [standalone]
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2022-03-08 22:30 +0100 |
| Message-ID | <DYPz3-rc3-15@gated-at.bofh.it> |
| In reply to | #246083 |
On Tuesday, 8 March 2022 16:06:54 EST tomas@tuxteam.de wrote: > On Tue, Mar 08, 2022 at 09:54:43PM +0100, tomas@tuxteam.de wrote: > > On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote: > > > Grettings all; > > > > > > Am I to assume that the kernel synaptic is installiing right now > > > fixes > > > dirty-pipe? > > > > > "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and > > 5.10.102." [1]> > > [1] https://lwn.net/Articles/887056/ > > Replying to self: ah, but this is CVE-2022-0847. According to [2], it > is fixed in current stable with kernel package 5.10.92-2. So yes. > > [2] https://www.debian.org/security/2022/dsa-5092 > -- > t Thank you Tomas. Heads up folks, update and reboot. Now if not sooner. Cheers, Gene Heskett. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [prev] | [next] | [standalone]
| From | gene heskett <gheskett@shentel.net> |
|---|---|
| Date | 2022-03-08 22:30 +0100 |
| Message-ID | <DYPz3-rc3-1@gated-at.bofh.it> |
| In reply to | #246081 |
On Tuesday, 8 March 2022 15:54:43 EST tomas@tuxteam.de wrote: > On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote: > > Grettings all; > > > > Am I to assume that the kernel synaptic is installiing right now > > fixes > > dirty-pipe? > > "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102." > [1] Ack uname, the image it just installed and I rebooted to is older, but the changelog does mention a new_pipe flag fix? So I'm confused. gene@coyote:~$ uname -a Linux coyote 5.10.0-11-amd64 #1 SMP Debian 5.10.92-2 (2022-02-28) x86_64 GNU/Linux > [1] https://lwn.net/Articles/887056/ > > -- > t Cheers, Gene Heskett. -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author, 1940) If we desire respect for the law, we must first make the law respectable. - Louis D. Brandeis
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2022-03-08 22:50 +0100 |
| Message-ID | <DYPSp-riq-9@gated-at.bofh.it> |
| In reply to | #246081 |
tomas@tuxteam.de [2022-03-08 21:54:43] wrote:
> On Tue, Mar 08, 2022 at 03:36:35PM -0500, gene heskett wrote:
>> Grettings all;
>> Am I to assume that the kernel synaptic is installiing right now fixes
>> dirty-pipe?
> "The vulnerability was fixed in Linux 5.16.11, 5.15.25 and 5.10.102." [1]
> [1] https://lwn.net/Articles/887056/
And for Debian, the details can be found:
https://security-tracker.debian.org/tracker/CVE-2022-0847
-- Stefan
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2022-03-08 22:20 +0100 |
| Message-ID | <DYPpn-r8P-3@gated-at.bofh.it> |
| In reply to | #246079 |
gene heskett wrote:
> Grettings all;
>
> Am I to assume that the kernel synaptic is installiing right now fixes
> dirty-pipe?
Yes, assuming that you're getting a linux kernel update for
Bullseye today.
Package : linux
CVE ID : CVE-2021-43976 CVE-2022-0330 CVE-2022-0435
CVE-2022-0516
CVE-2022-0847 CVE-2022-22942 CVE-2022-24448
CVE-2022-24959
CVE-2022-25258 CVE-2022-25375
2022-0847 is called "Dirty Pipe".
https://dirtypipe.cm4all.com/
-dsr-
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web