Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #879360

Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default

From Ben Hutchings <ben@decadent.org.uk>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default
Date 2018-02-03 14:20 +0100
Message-ID <vf5JT-3BN-11@gated-at.bofh.it> (permalink)
References (2 earlier) <veQ89-1wq-3@gated-at.bofh.it> <veS0h-2O6-3@gated-at.bofh.it> <veUbM-4l2-1@gated-at.bofh.it> <vevn3-4z6-5@gated-at.bofh.it> <veUbM-4l2-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Sat, 2018-02-03 at 00:45 +0000, Craig Small wrote:
> Hi Antoine (and kernel and security teams),
>   Thanks for giving me the background as it's a kernel vulnerability not a
> Procps one I wasn't aware of it.

It's not a kernel vulnerability, but a class of application
vulnerabilities that the kernel can protect against.

Ben.

> The change to Procps is pretty simple but given that you need to be running
> a non Debian kernel without this parameter what's groups' opinion of the
> urgency?
> 
> I can throw in the sysctl configuration file and upload a release this
> weekend if the consensus is it's needed or wait for the next upstream
> Procps release which would be a month or so away.

-- 
Ben Hutchings
Every program is either trivial or else contains at least one bug

Back to linux.debian.bugs.dist | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Antoine Beaupré <anarcat@debian.org> - 2018-02-01 23:20 +0100
  Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Moritz Mühlenhoff <jmm@inutil.org> - 2018-02-02 21:30 +0100
    Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Antoine Beaupré <anarcat@debian.org> - 2018-02-02 23:30 +0100
      Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Craig Small <csmall@debian.org> - 2018-02-03 02:00 +0100
        Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Ben Hutchings <ben@decadent.org.uk> - 2018-02-03 14:20 +0100
    Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Salvatore Bonaccorso <carnil@debian.org> - 2018-02-03 11:00 +0100
      Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default Antoine Beaupré <anarcat@debian.org> - 2018-02-03 15:50 +0100

csiph-web