grsecurity stop this crash?

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

grsecurity stop this crash?

Postby Lem0nHead » Mon Jun 14, 2004 8:44 am

anyone knows if grsecurity stop this crash?

http://linuxreviews.org/news/2004-06-11 ... index.html

thanks
Lem0nHead
 
Posts: 5
Joined: Wed Apr 14, 2004 1:09 am

Re: grsecurity stop this crash?

Postby PaX Team » Mon Jun 14, 2004 4:59 pm

PaX Team
 
Posts: 2310
Joined: Mon Mar 18, 2002 4:35 pm

Postby Loggy » Tue Jun 15, 2004 3:19 pm

This is a very dangerous program since it can't be stopped yet can be started by any user with access to the C compiler.

There are issues (a) to plug this hole by patching as it is only a one line change - which all sysadmins should clearly do - and (b) how grsecurity copes with this sort of thing.

From PaX's response, grsec won't stop it and this may take time to fix if there is any plan to tackle what could be a general class of security problems.

So two questions:

1 grsec is always based on vanilla kernels. Presumably the next vanilla kernel will include the simple fix. In the meantime, is there any policy about incorporating emergency patches - of any variety - in grsec either in the CVS download versions or by adding this patch to the standard grsec patches?

2 Are there any other such bombs around?
Loggy
 
Posts: 14
Joined: Tue Nov 18, 2003 5:28 am

Postby vietcgi » Tue Jun 15, 2004 9:45 pm

http://linuxreviews.org/news/2004-06-11 ... .patch.txt

this patch doesn't work with grsec.
vietcgi
 
Posts: 3
Joined: Tue Jun 15, 2004 9:42 pm

Postby Lem0nHead » Tue Jun 15, 2004 10:39 pm

vietcgi wrote:http://linuxreviews.org/news/2004-06-11_kernel_crash/24_kernel_ia32-and-x86_64-fix-fpu-state.patch.txt

this patch doesn't work with grsec.


what happens?
Lem0nHead
 
Posts: 5
Joined: Wed Apr 14, 2004 1:09 am

Postby Sleight of Mind » Tue Jun 15, 2004 10:46 pm

works fine really, i don't see the problem
Sleight of Mind
 
Posts: 92
Joined: Tue Apr 08, 2003 10:41 am

Postby Lem0nHead » Tue Jun 15, 2004 10:51 pm

well... i can't imagine why would it conflict
Lem0nHead
 
Posts: 5
Joined: Wed Apr 14, 2004 1:09 am

Postby vietcgi » Wed Jun 16, 2004 7:51 am

Lem0nHead wrote:well... i can't imagine why would it conflict


well, everything went fine, after I booted the new kernel, and ran the evil exploit, my server crashed...
vietcgi
 
Posts: 3
Joined: Tue Jun 15, 2004 9:42 pm


Return to grsecurity support

cron