Kernel root hole CVE-2010-3081 for stable release

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Kernel root hole CVE-2010-3081 for stable release

Postby cmouse » Tue Sep 21, 2010 3:04 am

For stable release, you can use this patch : http://git.kernel.org/?p=linux/kernel/g ... h=c41d68a5. It should go in OK, but I noticed that arch/tile/include/asm/compat.h will not go cleanly, as won't include/linux/compat.h. The first one you can just download from the site, and for the second one, just go ahead and add the line yourself. This will close the hole for your 2.6.32.21 kernel. http://cmouse.desteem.org/linux-2.6.32.21-cve20103081.patch for those who want a patch. This should go cleanly.
cmouse
 
Posts: 98
Joined: Tue Dec 17, 2002 10:58 am

Re: Kernel root hole CVE-2010-3081 for stable release

Postby spender » Tue Sep 21, 2010 7:49 am

Did you notice all the patches have already been included in grsec since the day the vulnerability was announced? ;)

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Re: Kernel root hole CVE-2010-3081 for stable release

Postby cmouse » Tue Sep 21, 2010 10:50 am

Weren't on my patch, you could've announced this on the news section :)
cmouse
 
Posts: 98
Joined: Tue Dec 17, 2002 10:58 am


Return to grsecurity support