There is upstream fix that should work for all debian editions[1]. See also
upstream ticket at[2]
[1] https://bug1634053.bmoattachments.org/attachment.cgi?id=9191200
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=1634053
Jordan
I think there are two aspects here. (In)security of unpriv user ns is one of
them - personally I'm in favor of opinions from people who argue that the
attack vector they open will remain for foreseeable future because kernel is
simply too big to fix all bugs. The other thing is that containers &
The fix [1] for PATH issue was sent long time ago to debian package
repository but it seem no longer maintained.
[1] https://salsa.debian.org/auth-team/yubikey-luks/merge_requests/1
Jordan
This bug is fixed upstream with:
https://github.com/cornelinux/yubikey-luks/commit/e6c20a349b0d7f3d02c69bf86ef2ab179691bb1e
which don't rely on cryptsetup package internals anymore but needs manual
system config adjustment.
There are also couple more fixes in master, including debian downstream
I think this bug can be closed now.
Jordan
linux-grsec-base[1] is missing from stable-backports and I don't see it being
prepared for upload there[2]. Other than that this bug can be closed. Thanks
for your work.
[1] https://tracker.debian.org/pkg/linux-grsec-base
[2] https://anonscm.debian.org/git/collab-maint/linux-grsec-base.git
I saw that new version landed in unstable. Is it possible to have it in
stable-backports? I think it will be best to have it in stable-backports ONLY
(without unstable) where it can live until 4.9 kernel gets EOL. In case of
unstable the gap between vanilla kernel and 4.9 will get bigger and big
Thank you for the reply. It's great that you consider packaging one of the
forward ports.
Just one more question - Is it possible for you to update current package to
latest official version (from 4.9.18 to 4.9.24)? That would be nice temporary
solution while you are too busy to make general dec
Source: linux-grsec
Severity: serious
I wanted to ask you about the future of linux-grsec in debian. The package
wasn't updated for some time and it's now at 4.9.18 version while last official
grsecurity version is 4.9.24. Additionally there are few forward ports of
grsecurity for 4.9 LTS kernel
9 matches
Mail list logo