From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: bug#27429: Stack clash (CVE-2017-1000366 etc) Date: Fri, 23 Jun 2017 14:54:48 -0400 Message-ID: <20170623185448.GA14284@jasmine.lan> References: <20170619222550.GA29289@jasmine.lan> <20170620004920.GB31586@jasmine.lan> <20170620071857.GA2768@macbook42.flashner.co.il> <87shiumj05.fsf@netris.org> <20170621084134.GA2870@macbook42.flashner.co.il> <20170621095045.GB2870@macbook42.flashner.co.il> <20170623172038.GA6052@jasmine.lan> <87mv8yh7pi.fsf@netris.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="OgqxwSJOaUobr8KG" Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:49066) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dOTjV-0007Jc-GB for bug-guix@gnu.org; Fri, 23 Jun 2017 14:55:06 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dOTjS-0007yW-E1 for bug-guix@gnu.org; Fri, 23 Jun 2017 14:55:05 -0400 Received: from debbugs.gnu.org ([208.118.235.43]:60308) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dOTjS-0007yL-6V for bug-guix@gnu.org; Fri, 23 Jun 2017 14:55:02 -0400 Sender: "Debbugs-submit" Resent-Message-ID: Content-Disposition: inline In-Reply-To: <87mv8yh7pi.fsf@netris.org> List-Id: Bug reports for GNU Guix List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-guix-bounces+gcggb-bug-guix=m.gmane.org@gnu.org Sender: "bug-Guix" To: Mark H Weaver Cc: 27429@debbugs.gnu.org --OgqxwSJOaUobr8KG Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Fri, Jun 23, 2017 at 02:36:41PM -0400, Mark H Weaver wrote: > Most packages are linked with 'glibc-final' in (gnu packages > commencement), and we should expect them to now be linked with *its* > replacement. Try this to find the expected glibc-final replacement: >=20 > ./pre-inst-env guix build -e '((@@ (guix packages) package-replacement)= (@@ (gnu packages commencement) glibc-final))' Thank you for the clarification. Indeed, with Efraim's latest patch, packages seem to be referring to the replacement for glibc-final. So, do we think this patch is ready to apply? AFAIK, nobody has yet tried upgrading a GuixSD system with this patch. I won't have access to my bare-metal GuixSD system for the next few days. > > By the way, Qualys will probably begin publishing their exploits on > > Tuesday [0]: >=20 > Thanks for the heads-up, and more generally to your prolific > contributions to security in Guix! Thank you for your advice and guidance, and to Efraim for taking the lead on fixing this bug! --OgqxwSJOaUobr8KG Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAABCAAdFiEEsFFZSPHn08G5gDigJkb6MLrKfwgFAllNY/UACgkQJkb6MLrK fwjeBRAAgr2wvk4iDusBQ9WA95RLb7CuZGE1pqw/dtaciWOKsadtvaX2RtSWNljD FrIv7ElHV2C9aRbEBjOcVKTIRw//i6Wj9id4AX3h1qPLu2jFn5cl3eYxuWTrV7no /tqg1nehTG9lJx6QuNIf8+mWdiBSB1vTzSjEMDrDOwo89HgRaxeuijopBPlAJdZa FbDv0L3EX1SX27iW/yihjm3J4icbi6C3WMoex9ZXGW2Al1XAMpspZCFkAWTnb/ol e72Io592sXTsscSCdLfLTTNvXmUZmXJ/W/ewSauhrtMcHcLpc5DWlAcgSnvqaJVz lNJSmiRKxB1NH81NtVYLzCCLwCIuUmh7tzzhPoyhibF5I8d2nAVLx2Yq/i1H8SbW rOZQPqt+LChMv5AYQV8EylXCvPzh/1R6NlpZRgvwa94JZFoAFdMdhv7BVpOgpA1c zWx724Pb0PpI36xysn7PSkCDFnl3kJSUCPwcfWAgo4GOuosj0cYFRznGBTRFWZyq DFP8FYj3pyXmPEiv9XnOSTzYGjKUFUBix/vrMBBuU3MforI4N3Y4W2uTwKBsDc6F xCr1hDmuCRXANJMal2UETEYrsL99vEbriNJzPo47msbgZesYO9mW9rATOThVAv3I nwNbDFMK0RJnmsplpNJJWGF10HauVOJRV7YUn872mRT04gvqmPo= =GdEK -----END PGP SIGNATURE----- --OgqxwSJOaUobr8KG--