Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20141206153527.GA28777@kroah.com>
Date: Sat, 6 Dec 2014 07:35:27 -0800
From: Greg KH <greg@...ah.com>
To: oss-security@...ts.openwall.com
Subject: Re: How GNU/Linux distros deal with offset2lib attack?

On Sat, Dec 06, 2014 at 03:22:58PM +0800, Shawn wrote:
> 
> 2, ASLRv3? Hector Marco( the dude who disclosured offset2lib attack)
> sent a patch to the upstream:
> https://lkml.org/lkml/2014/12/4/839
> 
> Even the upstream don't accept the patch, is this possible to backport
> it & maintain it for distro community?

Upstream asked for some basic fixes to the patch (i.e. it wasn't
submitted in the needed format) before it could accept it, so I doubt
it's rejected yet.

And of course a distro could backport and maintain it, it's a very tiny
patch, much smaller than what they normall backport.  Take it up with
the distros if you want this.

thanks,

greg k-h

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.