public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* Linux 2.4.33.2
@ 2006-08-22 21:23 Willy Tarreau
  2006-08-23  2:08 ` Grant Coady
  0 siblings, 1 reply; 9+ messages in thread
From: Willy Tarreau @ 2006-08-22 21:23 UTC (permalink / raw)
  To: linux-kernel; +Cc: mtosatti, Patrick J. Volkerding, Grant Coady


Hi !

Linux 2.4.33.2 is out. It fixes a local privilege escalation in SCTP
(CVE-2006-3745). Also included are a fix for a bad address check in
binfmt_elf (already in 2.6), and a fix for build on some non-sparc
architectures which I broke in 2.4.33.1 when trying to fix the memchr()
export (problem reported by Mikael Pettersson).

If does not contain the UDF fix which went in 2.6.17.10. I will check
whether it applies to 2.4 and will backport it for a future release.

### Important note for users of Slackware 10.2 ###

Grant Coady informed me that 2.4.33.1 did not boot for him. After a long
series of tests from him and Pat Volkerding, it appeared that the problem
is caused by glibc 2.3.6 wrongly detecting kernel version as 4.33.1 and
mistakenly using the NTPL libs instead.

Patrick has fixed the problem and will (has ?) send the fix to the glibc
team. By now people using Slackware 10.2 must upgrade their glibc to
glibc-solibs-2.3.5-i486-6_slack10.2.tgz if they want to run a 2.4.33.x
kernel (user glibc-2.3.6 build -5 for -current). A workaround is either
to rename /lib/tls or to rename the kernel to something different than
4 numbers separated by dots. Since the problem is fixed, I don't intend
to change the numbering.

I dont think that this problem might affect many other distros since those
shipping an NPTL-enabled libc with both 2.4 and 2.6 mainline are rare. If
anyone else encounters the problem, Pat has the fix.


Regards,
Willy



Summary of changes from v2.4.33.1 to v2.4.33.2
============================================

Ernie Petrides:
      binfmt_elf.c : fix checks for bad address

Sridhar Samudrala:
      [SCTP] Local privilege elevation - CVE-2006-3745

Willy Tarreau:
      Revert "export memchr() which is used by smbfs and lp driver."
      [SPARC] export memchr() which is used by smbfs and lp driver.
      Change VERSION to 2.4.33.2



^ permalink raw reply	[flat|nested] 9+ messages in thread
* Re: Linux 2.4.33.2
@ 2006-08-27 12:35 Mikael Pettersson
  2006-08-27 14:50 ` Nick Warne
  2006-08-27 20:35 ` Grant Coady
  0 siblings, 2 replies; 9+ messages in thread
From: Mikael Pettersson @ 2006-08-27 12:35 UTC (permalink / raw)
  To: linux-kernel, wtarreau; +Cc: gcoady.lk, mtosatti, volkerdi

On Tue, 22 Aug 2006 21:23:00 +0000, Willy Tarreau wrote:
>### Important note for users of Slackware 10.2 ###
>
>Grant Coady informed me that 2.4.33.1 did not boot for him. After a long
>series of tests from him and Pat Volkerding, it appeared that the problem
>is caused by glibc 2.3.6 wrongly detecting kernel version as 4.33.1 and
>mistakenly using the NTPL libs instead.
>
>Patrick has fixed the problem and will (has ?) send the fix to the glibc
>team. By now people using Slackware 10.2 must upgrade their glibc to
>glibc-solibs-2.3.5-i486-6_slack10.2.tgz if they want to run a 2.4.33.x
>kernel (user glibc-2.3.6 build -5 for -current). A workaround is either
>to rename /lib/tls or to rename the kernel to something different than
>4 numbers separated by dots. Since the problem is fixed, I don't intend
>to change the numbering.
>
>I dont think that this problem might affect many other distros since those
>shipping an NPTL-enabled libc with both 2.4 and 2.6 mainline are rare. If
>anyone else encounters the problem, Pat has the fix.

Can anyone provide a URL to the glibc fix?
While I don't use Slackware and haven't been bitten by
the bug (yet), I want to review the fix for possible
inclusion in my glibc patch kit.

/Mikael

^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2006-08-29 21:20 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-08-22 21:23 Linux 2.4.33.2 Willy Tarreau
2006-08-23  2:08 ` Grant Coady
  -- strict thread matches above, loose matches on Subject: below --
2006-08-27 12:35 Mikael Pettersson
2006-08-27 14:50 ` Nick Warne
2006-08-27 16:28   ` Petri Kaukasoina
2006-08-27 16:31     ` Nick Warne
2006-08-29 21:09       ` Patrick J. Volkerding
2006-08-29 21:19         ` Nick Warne
2006-08-27 20:35 ` Grant Coady

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox