Re: [vserver] CVE-2016-10229: MSG_PEEK - URGENT patch needed

From: Corey Wright <undefined_at_pobox.com>
Date: Tue 02 May 2017 - 13:58:58 BST
Message-Id: <20170502075858.61f28b0b7f461673874e2810@pobox.com>

On Tue, 02 May 2017 10:13:58 +0100
Ben Green <ben@bristolwireless.net> wrote:

> Quoting Herbert Poetzl <herbert@13thfloor.at>:
>
> >> No reason other than it would be good for everyone to
> >> have it and I'm not sure how to create the Deb files
> >> like you do.
> >
> > I'm not creating any deb files, but I'm not Ben either ...
> >
> > And I'm certainly not speaking for him, but I think that
> > if you use his packages on a regular basis and kind of
> > 'depend' on them being up-to-date, you might consider
> > asking nicely for an update or maybe even donate something
> > to say thanks ...
>
> Hi all,
>
> I'd like a patched kernel too. I'm more than happy to compile a kernel
> and patchset that I'm given. The job of checking the patch against the
> vserver patched kernel is not one I'm keen to take on. I am very busy
> at the moment. If someone can confirm that the patch works for a
> vserver patched kernel, then the job of compiling, and a quick test of
> the result, is one I'm happy to take on.

i'm running 3.18.50-vs2.3.7.5 and will put into production
3.18.51-vs2.3.7.5 later this week, having already tested it.

my testing consists of testme.sh, testfs.sh (with ext[234]), and
creating a basic set of device files (eg null, ptmx, random, tty,
urandom) within a vserver where device permissions are enforced by
cgroup's devices.{allow,deny} (which is a use-case that silently broke
with a previous linux-vserver + upstream update iteration, so i added
it as a check-out test.)

still need to figure out why jessie lxc containers can only use a
single tty and only once (eg can't log into container twice
successively or simultaneously), but that happens on vanilla 3.18,
too. (need to try switching the container's init from systemd to sysv
the next time i experiment/debug.)

corey

--
undefined@pobox.com
> Donations always appreciated.
> 
> Cheers,
> Ben
Received on Tue May 2 13:59:09 2017
[Next/Previous Months] [Main vserver Project Homepage] [Howto Subscribe/Unsubscribe] [Paul Sladen's vserver stuff]
Generated on Tue 02 May 2017 - 13:59:09 BST by hypermail 2.1.8