Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #269371 > unrolled thread

Security hole in kernel fixed?

Started byHans <hans.ullrich@loop.de>
First post2024-05-15 09:10 +0200
Last post2024-05-16 05:30 +0200
Articles 3 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  Security hole in kernel fixed? Hans <hans.ullrich@loop.de> - 2024-05-15 09:10 +0200
    Re: Security hole in kernel fixed? The Wanderer <wanderer@fastmail.fm> - 2024-05-15 13:10 +0200
    Re: Security hole in kernel fixed? Stanislav Vlasov <stanislav.v.v@gmail.com> - 2024-05-16 05:30 +0200

#269371 — Security hole in kernel fixed?

FromHans <hans.ullrich@loop.de>
Date2024-05-15 09:10 +0200
SubjectSecurity hole in kernel fixed?
Message-ID<IEgVX-dtca-7@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

Dear developers,


in April 2024 the security hole CVE-2023-6546 was discovered in linux-image, and I believe, it 
is fixed in kernel 6.1.0 (from debian/stable) as soon after this a new kernel was released.


However, there is no new kernel 6.5.0-*-bpo released at that time, so my question: 


Does anyone know, if this fix was also integrated in kernel 6.5.0-*.bpo ?

Thanks for your answer.

Best

Hans




[toc] | [next] | [standalone]


#269376

FromThe Wanderer <wanderer@fastmail.fm>
Date2024-05-15 13:10 +0200
Message-ID<IEkGd-dvs7-7@gated-at.bofh.it>
In reply to#269371

[Multipart message — attachments visible in raw view] — view raw

On 2024-05-15 at 03:05, Hans wrote:

> Dear developers,

As usual, most of us here are not Debian developers, even if some of us
may be software developers.

> in April 2024 the security hole CVE-2023-6546 was discovered in linux-image, and I believe, it 
> is fixed in kernel 6.1.0 (from debian/stable) as soon after this a new kernel was released.
> 
> However, there is no new kernel 6.5.0-*-bpo released at that time, so my question: 
> 
> Does anyone know, if this fix was also integrated in kernel 6.5.0-*.bpo ?

I don't have a definitive answer, but you might look at:

https://security-tracker.debian.org/tracker/CVE-2023-6546

The only place it mentions 6.5 is in the Notes section, where it
mentions 6.5-rc7 (with a kernel.org link) in the context of a statement
that the Linux kernel in Debian buster does not include the vulnerable
code.

I would therefore suspect that any 6.5.x kernel probably was not
affected by this vulnerability to begin with.

-- 
   The Wanderer

The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man.         -- George Bernard Shaw

[toc] | [prev] | [next] | [standalone]


#269392

FromStanislav Vlasov <stanislav.v.v@gmail.com>
Date2024-05-16 05:30 +0200
Message-ID<IEzYB-dEvm-3@gated-at.bofh.it>
In reply to#269371
ср, 15 мая 2024 г. в 16:55, Hans <hans.ullrich@loop.de>:

> Dear developers,

Users.

> in April 2024 the security hole CVE-2023-6546 was discovered in linux-image, and I believe, it is fixed in kernel 6.1.0 (from debian/stable) as soon after this a new kernel was released.

https://security-tracker.debian.org/tracker/CVE-2023-6546 may be help

-- 
Stanislav

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web