oss-sec mailing list archives
Re: Qualys Security Advisory - The Stack Clash
From: "kseifried () redhat com" <kseifried () redhat com>
Date: Wed, 21 Jun 2017 10:06:39 -0600
On 06/21/2017 09:15 AM, Stuart Henderson wrote:
On 2017/06/21 16:36, Solar Designer wrote:Granted, they can now prepare their updates within hours or days due to the work done by SUSE, Red Hat, and others on the distros list, hopefully in time before attacks using the Qualys findings start or become widespread, but nevertheless they are at a disadvantage.People doing this might want to note that Icinga ran into problems with the fix in RHEL/Centos kernels when using setrlimit to restrict the stack size below the default. The Red Hat ticket is currently locked but there's some information at https://bugs.centos.org/view.php?id=13453.
Ah sorry about that, I've made https://bugzilla.redhat.com/show_bug.cgi?id=1463241 public, kernel bugs default to private and then typically get opened up (mostly because people have a tendency to put traces/dumps with sensitive information in them and we don't want someone accidentally exposing their SSH host keys or whatever). -- Kurt Seifried -- Red Hat -- Product Security -- Cloud PGP A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 Red Hat Product Security contact: secalert () redhat com
Current thread:
- Re: Qualys Security Advisory - The Stack Clash, (continued)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 20)
- Re: Qualys Security Advisory - The Stack Clash Qualys Security Advisory (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash nospam (Jun 21)
- Re: Re: Qualys Security Advisory - The Stack Clash Franz Pletz (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 25)
- Re: Qualys Security Advisory - The Stack Clash Qualys Security Advisory (Jun 28)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 19)
- Re: Qualys Security Advisory - The Stack Clash Josh Bressers (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Stuart Henderson (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash kseifried () redhat com (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Qualys Security Advisory (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Jeff Law (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Daniel Micay (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Florian Weimer (Jun 22)
- Re: Qualys Security Advisory - The Stack Clash Brad Spengler (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Solar Designer (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Daniel Micay (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Brad Spengler (Jun 21)
- Re: Qualys Security Advisory - The Stack Clash Mike O'Connor (Jun 22)