Ubuntu kernel update and grsecurity?

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Ubuntu kernel update and grsecurity?

Postby pdh0710 » Mon Nov 03, 2014 6:55 pm

(Please excuse my English)

Hi... I am a newbie for grsecurity and have a basic question.

I'm planning to install grsecurity in a Ubuntu 14.04 system. The kernel verion of Ubuntu 14.04 is 3.13
and most recent grsecurity stable is for kernel 3.14.23 (grsecurity-3.0-3.14.23-201410312212.patch).
So I think grsecurity is good for enhancing security of Ubuntu 14.04. Am I right?

However I wonder... If Ubuntu updates its kernel(Ubuntu frequently updates and patches its kernel),
what happens? The kernel update will be also good for grsecurity installed Ubuntu? Or will make
kernel panic?
Last edited by pdh0710 on Tue Nov 04, 2014 1:08 pm, edited 2 times in total.
pdh0710
 
Posts: 7
Joined: Sun Oct 26, 2014 5:19 am

Re: Ubuntu kernel update and grsecurity?

Postby N8Fear » Tue Nov 04, 2014 6:28 am

grsecurity is a kernel patch and as such applied to the sources of the kernel before compiling it. You should match kernel version and grsecurity patch version, e.g. if you want to use grsecurity-3.0-3.14.23-201410312212.patch you should apply that to the 3.14.23 sources.
Unless Ubuntu provides grsecurity patched kernels you don't have to care about ubuntu's kernels (as you don't use them anyways).
N8Fear
 
Posts: 37
Joined: Thu Jan 17, 2013 5:01 am

Re: Ubuntu kernel update and grsecurity?

Postby pdh0710 » Tue Nov 04, 2014 1:03 pm

Thank you, N8Fear. I can understand more clearly.

Then, suppose that I installed grsecurity in Ubuntu 14.04, using kernel 3.14.23 and grsecurity-3.0-3.14.23-201410312212.patch.
After then, Linux kernel is updated to 3.14.24 (Linux kernels are frequently updated, too). What should I do? Just wait for
grsecurity new version for kernel 3.14.24? Or do something else?
pdh0710
 
Posts: 7
Joined: Sun Oct 26, 2014 5:19 am

Re: Ubuntu kernel update and grsecurity?

Postby spender » Tue Nov 04, 2014 7:21 pm

Just wait for grsecurity to update. Generally updates are made the same day as upstream and all the important security fixes have already been applied weeks prior to them appearing in the updated upstream -stable kernel.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Re: Ubuntu kernel update and grsecurity?

Postby pdh0710 » Tue Nov 04, 2014 8:00 pm

O.K. I can understand that I do not have to worry about kernel update.
Thank you, Brad.
pdh0710
 
Posts: 7
Joined: Sun Oct 26, 2014 5:19 am


Return to grsecurity support