Re: hardened-sources wrt CVE-2014-3153 and CVE-2014-0196

"Anthony G. Basile" <[email protected]>
Newsgroups gmane.linux.gentoo.hardened
Message-ID <[email protected]>
On 06/07/14 17:51, "Tóth Attila" wrote:
> 2014.Június 7.(Szo) 15:07 időpontban Anthony G. Basile ezt írta:
>> This is one of those rare situations where there are enough serious bugs
>> against the kernel that we may have to rapid stabilize
>> hardened-sources-3.2.59-r5 and 3.14.5-r2.  These are currently marked ~
>> because I need feedback from users.  So please try to upgrade to either
>> one (3.2 is preferred for mission critical) and give me feedback.  The
>> only caution is do not enable KSTACKOVERFLOW, a new option which is know
>> to cause panics, eg virtio iface.
>
> I'm running hardened-sources-3.14.5 since Tuesday, and rebooted into
> hardened-sources-3.14.5-r2 on Saturday. I kept KSTACKOVERFLOW enabled for
> both kernels and experienced no crashes so far on two systems.
>
> Dw.
>

You can try KSTACKOVERFLOW.  When I hit the issue with virtio iface, it 
panicked as soon as the init scripts brought it up.  When I switched to 
e1000 it worked fine.

So if it works with your devices you're probably safe.  Still, if you're 
running some mission critical stuff, don't use it just in case.

-- 
Anthony G. Basile, Ph. D.
Chair of Information Technology
D'Youville College
Buffalo, NY 14201
(716) 829-8197
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.