|
Message-ID: <2ef801a78bca95eb9f7ffba8ed26e14c@smtp.hushmail.com> Date: Wed, 3 Apr 2019 22:37:39 +0100 From: Paweł Krawczyk <pawel.krawczyk@...h.com> To: lkrg-users@...ts.openwall.com Subject: Whitelisting LivePatch I'm hitting this false positive quite frequently and I was just wondering if there is any way to modify p_lkrg to whitelist this type of changes? What Canonical LivePatch does is, well, essentially patch the living kernel which obviously changes the code signature. LivePatch works through a kernel module called lkp_Ubuntu_4_15_0_45_48_generic_49 (or similar). Apr 2 11:58:43 otto kernel: [3675742.580321] livepatch: enabling patch 'lkp_Ubuntu_4_15_0_45_48_generic_49' Apr 2 11:58:43 otto kernel: [3675742.585073] livepatch: 'lkp_Ubuntu_4_15_0_45_48_generic_49': starting patching transition Apr 2 11:58:43 otto kernel: [3675742.740469] [p_lkrg] ALERT !!! _STEXT MEMORY BLOCK HASH IS DIFFERENT - it is [0x918a7a1fc13e7dc9] and should be [0xfb806a7dd458b274] !!! Apr 2 11:58:43 otto kernel: [3675742.743774] [p_lkrg] ALERT !!! SYSTEM HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!! Apr 2 11:58:44 otto kernel: [3675743.259222] [p_lkrg] ALERT !!! _STEXT MEMORY BLOCK HASH IS DIFFERENT - it is [0x918a7a1fc13e7dc9] and should be [0xfb806a7dd458b274] !!! Apr 2 11:58:44 otto kernel: [3675743.262512] [p_lkrg] ALERT !!! SYSTEM HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!! Apr 2 11:58:44 otto kernel: [3675743.834990] [p_lkrg] ALERT !!! _STEXT MEMORY BLOCK HASH IS DIFFERENT - it is [0x918a7a1fc13e7dc9] and should be [0xfb806a7dd458b274] !!! Apr 2 11:58:44 otto kernel: [3675743.837264] [p_lkrg] ALERT !!! SYSTEM HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!! Apr 2 11:58:45 otto kernel: [3675744.201058] livepatch: 'lkp_Ubuntu_4_15_0_45_48_generic_49': patching complete -- Paweł Krawczyk +44 7879 180015
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.