Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: CVE-2012-0056
PostPosted: Wed Jan 25, 2012 7:15 pm 
Offline
Junior Member

Joined: Fri Mar 05, 2004 12:30 am
Posts: 39
ICQ: 181450
Website: http://tkatch.com
AOL: TMHChacham
Location: Oak Park, MI
I'm running Debian squeeze: uname -r -> 2.6.39.1-linode34

Debian says this is fixed: http://security-tracker.debian.org/trac ... -2012-0056

I am vulnerable: http://grsecurity.net/~spender/correct_ ... producer.c

(download code to a.c; make a.c; ./a)

(nice instructions here: http://www.outflux.net/blog/archives/20 ... systemtap/)

I would like to fix/patch this, but am not quite sure what to do.


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 7:19 pm 
Offline
Junior Member

Joined: Thu Nov 25, 2010 7:41 pm
Posts: 27
Edit the configuration profile for your Linode, select the latest kernel (3.2.1) and reboot.


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 7:20 pm 
Offline
Sysop

Joined: Sat Nov 27, 2010 3:32 am
Posts: 180
Website: https://blog.timheckman.net/
Location: San Francisco, CA
We've released new Linode kernels to address this issue.

32-bit: "Latest 3.0 (3.0.17-linode41)"
64-bit: "Latest 3.2 (3.2.1-x86_64-linode23)"

Simply select the respective kernel for your Linode in the configuration profile and reboot.

-Tim


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 7:28 pm 
Offline
Senior Newbie

Joined: Fri Jun 20, 2008 8:51 am
Posts: 9
It's also worth noting that, if I am reading correct_proc_mem_reproducer.c right, it does not test if you are vulnerable to CVE-2012-0056, but rather only tests if you have applied the systemtap patch or not.

So don't freak out if the test says you're "vulnerable" on a patched kernel.


Last edited by bss on Wed Jan 25, 2012 7:29 pm, edited 1 time in total.

Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 7:29 pm 
Offline
Senior Member

Joined: Sun May 23, 2010 1:57 pm
Posts: 315
Website: http://www.jebblue.net
Glad chacham asked the question or I wouldn't have known. Shouldn't an email have gone out saying "your current kernel is deprecated due to a serious security risk please login, choose the latest and reboot"?


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 7:52 pm 
Offline
Senior Member

Joined: Sun Mar 07, 2010 7:47 pm
Posts: 1970
Website: http://www.rwky.net
Location: Earth
It was posted here http://www.linode.com/kernels/ they have an rss feed you can subscribe to

_________________
Paid support
How to ask for help
1. Give details of your problem
2. Post any errors
3. Post relevant logs.
4. Don't hide details i.e. your domain, it just makes things harder
5. Be polite or you'll be eaten by a grue


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 8:14 pm 
Offline
Junior Member

Joined: Fri Mar 05, 2004 12:30 am
Posts: 39
ICQ: 181450
Website: http://tkatch.com
AOL: TMHChacham
Location: Oak Park, MI
You guys rock!

It's as easy as

1) Edit
2) Save
3) Reboot

I second the notion of a security email.

As for the code, seem right. After the reboot, it still told me i was vulnerable.

uname -r - >3.0.17-linode41


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 8:23 pm 
Offline
Junior Member

Joined: Fri Mar 05, 2004 12:30 am
Posts: 39
ICQ: 181450
Website: http://tkatch.com
AOL: TMHChacham
Location: Oak Park, MI
And it is fixed. hack tried by my local script kiddie. :)


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 8:24 pm 
Offline
Senior Member
User avatar

Joined: Fri Oct 24, 2003 3:51 pm
Posts: 965
Location: Netherlands
chacham wrote:
I second the notion of a security email.

Linode is an unmanaged service -- it's up to us to keep an eye on this sort of thing. Subscribe to this: www.linode.com/kernels/rss.xml.

_________________
/ Peter


Top
   
 Post subject:
PostPosted: Wed Jan 25, 2012 10:02 pm 
Offline
Junior Member

Joined: Fri Mar 05, 2004 12:30 am
Posts: 39
ICQ: 181450
Website: http://tkatch.com
AOL: TMHChacham
Location: Oak Park, MI
Thanx for the link.

The RSS feed doesn't mention severity. I understand it doesn't have to. But it'd be nice to have a list (or even this or another RSS feed) to bring critical patches to mind.


Top
   
 Post subject:
PostPosted: Thu Jan 26, 2012 1:17 am 
Offline
Senior Member

Joined: Sun May 23, 2010 1:57 pm
Posts: 315
Website: http://www.jebblue.net
pclissold wrote:
chacham wrote:
I second the notion of a security email.

Linode is an unmanaged service -- it's up to us to keep an eye on this sort of thing. Subscribe to this: www.linode.com/kernels/rss.xml.


Perhaps Linode should then also remove these useful services:

http://www.linode.com/features.cfm


Top
   
 Post subject:
PostPosted: Thu Jan 26, 2012 10:12 am 
Offline
Junior Member
User avatar

Joined: Mon Jun 20, 2011 8:54 am
Posts: 44
<2 cents>
Those are on-demand, automated features that let us manage our 'nodes ourselves, not services they perform for us. Would it be nice if they provided a notice? Sure, but not everyone can change kernels without testing software first. And not everyone wants Linode tracking what they're doing with their Linode :wink: Plus there are already plenty of security services out there that let people track vulnerabilities, including email lists. Anyone worried enough about kernel vuln's should already be looking at those. Internet Storm Center is a good place to start feeling paranoid, plus help you find stuff to mitigate threats (e.g.: the DShield Block List)

</2 cents>


Top
   
 Post subject:
PostPosted: Thu Jan 26, 2012 12:00 pm 
Offline
Junior Member

Joined: Fri Mar 05, 2004 12:30 am
Posts: 39
ICQ: 181450
Website: http://tkatch.com
AOL: TMHChacham
Location: Oak Park, MI
Note, that even if we know of the vulnerabilities, we can't do anything without a kernel available here. Hence, they have to fix it. So, if they do, it'd be nice if they told us about it.

A wish, that's all.


Top
   
 Post subject:
PostPosted: Thu Jan 26, 2012 12:29 pm 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
chacham wrote:
Note, that even if we know of the vulnerabilities, we can't do anything without a kernel available here. Hence, they have to fix it. So, if they do, it'd be nice if they told us about it.

A wish, that's all.


That's incorrect. You can load whatever kernel you want, so you can do something, and they don't have to fix it for you to be protected.


Top
   
 Post subject:
PostPosted: Thu Jan 26, 2012 12:49 pm 
Offline
Junior Member

Joined: Fri Mar 05, 2004 12:30 am
Posts: 39
ICQ: 181450
Website: http://tkatch.com
AOL: TMHChacham
Location: Oak Park, MI
Hmm... i assumed wrongly then. i thought the reason for the -linode kernels was that they were required.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group