Re: hardened-sources wrt CVE-2014-3153 and CVE-2014-0196
"Anthony G. Basile" <[email protected]>
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <[email protected]> |
On 06/07/14 17:51, "Tóth Attila" wrote: > 2014.Június 7.(Szo) 15:07 időpontban Anthony G. Basile ezt írta: >> This is one of those rare situations where there are enough serious bugs >> against the kernel that we may have to rapid stabilize >> hardened-sources-3.2.59-r5 and 3.14.5-r2. These are currently marked ~ >> because I need feedback from users. So please try to upgrade to either >> one (3.2 is preferred for mission critical) and give me feedback. The >> only caution is do not enable KSTACKOVERFLOW, a new option which is know >> to cause panics, eg virtio iface. > > I'm running hardened-sources-3.14.5 since Tuesday, and rebooted into > hardened-sources-3.14.5-r2 on Saturday. I kept KSTACKOVERFLOW enabled for > both kernels and experienced no crashes so far on two systems. > > Dw. > You can try KSTACKOVERFLOW. When I hit the issue with virtio iface, it panicked as soon as the init scripts brought it up. When I switched to e1000 it worked fine. So if it works with your devices you're probably safe. Still, if you're running some mission critical stuff, don't use it just in case. -- Anthony G. Basile, Ph. D. Chair of Information Technology D'Youville College Buffalo, NY 14201 (716) 829-8197