* linux-libre@4.1 lacks Stack Clash mitigation; reaches EOL soon @ 2017-06-28 5:05 Mark H Weaver 2017-06-29 16:44 ` Mark H Weaver 0 siblings, 1 reply; 3+ messages in thread From: Mark H Weaver @ 2017-06-28 5:05 UTC (permalink / raw) To: guix-devel Users of linux-libre@4.1 should take notice: I've been unable to find backported patches for CVE-2017-1000364 (Stack Clash mitigation) for linux-4.1. Also, upstream support for that kernel version will reach end-of-life in about a month, so you should plan to migrate to another kernel version soon. Mark ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: linux-libre@4.1 lacks Stack Clash mitigation; reaches EOL soon 2017-06-28 5:05 linux-libre@4.1 lacks Stack Clash mitigation; reaches EOL soon Mark H Weaver @ 2017-06-29 16:44 ` Mark H Weaver 2017-06-30 5:06 ` Mark H Weaver 0 siblings, 1 reply; 3+ messages in thread From: Mark H Weaver @ 2017-06-29 16:44 UTC (permalink / raw) To: guix-devel linux-4.1.42 has just been released, which includes a backport of the Stack Clash mitigation. Hopefully the corresponding linux-libre release will be out in the next day or so. If you're impatient, you could cherry-pick the following two commits: https://git.kernel.org/pub/scm/linux/kernel/git/sashal/linux-stable.git/commit/?h=linux-4.1.y&id=8b18c6b2a0dde5186ed83a60c4915c0909cbeb0a https://git.kernel.org/pub/scm/linux/kernel/git/sashal/linux-stable.git/commit/?h=linux-4.1.y&id=dcda279dede75d5cb4e6af18ba90eb4ca1e813ee It would be similar to commit 91c623aae0f10992aa46957b9072679534e4cd28, but applied only to linux-libre-4.1. Mark ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: linux-libre@4.1 lacks Stack Clash mitigation; reaches EOL soon 2017-06-29 16:44 ` Mark H Weaver @ 2017-06-30 5:06 ` Mark H Weaver 0 siblings, 0 replies; 3+ messages in thread From: Mark H Weaver @ 2017-06-30 5:06 UTC (permalink / raw) To: guix-devel Mark H Weaver <mhw@netris.org> writes: > linux-4.1.42 has just been released, which includes a backport of the > Stack Clash mitigation. Hopefully the corresponding linux-libre release > will be out in the next day or so. I just pushed the update to linux-libre-4.1.42. Mark ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2017-06-30 5:06 UTC | newest] Thread overview: 3+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2017-06-28 5:05 linux-libre@4.1 lacks Stack Clash mitigation; reaches EOL soon Mark H Weaver 2017-06-29 16:44 ` Mark H Weaver 2017-06-30 5:06 ` Mark H Weaver
Code repositories for project(s) associated with this public inbox https://git.savannah.gnu.org/cgit/guix.git This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).