[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bug#889098: enforce fs.protected_hardlinks in sysctl.d by default



On Sat, 2018-02-03 at 00:45 +0000, Craig Small wrote:
> Hi Antoine (and kernel and security teams),
>   Thanks for giving me the background as it's a kernel vulnerability not a
> Procps one I wasn't aware of it.

It's not a kernel vulnerability, but a class of application
vulnerabilities that the kernel can protect against.

Ben.

> The change to Procps is pretty simple but given that you need to be running
> a non Debian kernel without this parameter what's groups' opinion of the
> urgency?
> 
> I can throw in the sysctl configuration file and upload a release this
> weekend if the consensus is it's needed or wait for the next upstream
> Procps release which would be a month or so away.

-- 
Ben Hutchings
Every program is either trivial or else contains at least one bug

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: