From: Tom Hendrikx <tom@whyscream.net>
To: gentoo-hardened@lists.gentoo.org
Subject: Re: [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2
Date: Fri, 03 Feb 2012 15:11:36 +0100 [thread overview]
Message-ID: <4F2BEB18.9090604@whyscream.net> (raw)
In-Reply-To: <4F2BD518.2090702@whyscream.net>
On 03/02/12 13:37, Tom Hendrikx wrote:
> On 03/02/12 03:50, Brian Kroth wrote:
>> Tom Hendrikx <tom@whyscream.net> 2012-02-02 21:42:
>>> On 27/01/12 14:37, Anthony G. Basile wrote:
>>>> Hi everyone,
>>>>
>>>> I just added hardened-sources 2.6.32-r88 and 3.2.2 to the tree. They
>>>> address CVE-2012-0056. I've tested and they do indeed resist the
>>>> exploit. I will be stabilizing them within 24 hours. However, I feel
>>>> very uncomfortable doing so because I don't want to trade one set of
>>>> problems with another. If anyone has time to test, let me know if you
>>>> encounter any issues.
>>>>
>>>
>>> I am still using 2.6.* sources here on one machine pending resolution of
>>> bug https://bugs.gentoo.org/show_bug.cgi?id=386721 (if it will ever
>>> happen :/ ).
>>
>> Are those open-vm kernel modules still necessary? It was my
>> understanding that most/all of the guest modules for more efficient
>> virtual hardware support were included in the mainline kernel now:
>> <http://kernelnewbies.org/Linux_2_6_33#head-b1a0ddbc804d228802ce8aebd37d9fd6513ccb01>
>>
>
> I did some more investigation. None of the three in-tree
> open-vm-tools-kmod ebuilds compile against 2.6.32-r89, building a
> 3.2.2-r1 kernel now to test against that.
The same goes for 3.2.2-r1: none of the -kmod packages build against it.
this means that the state of the -kmod package is a security issue,
since it cannot be used with a non-vulnerable -hardened kernel. I'll add
this to the bug report.
>
> I thought that I needed the -kmod package to run open-vm-tools in the
> guest, but after some more research this might only apply when you want
> drag-and-drop support (useless for (headless) server). The open-vm-tools
> ebuilds list the -kmod package as a hard RDEPEND though. I'll do some
> tests later today/during the weekend.
>
Just booted a 3.2.2-r1-hardened kernel, and vmware-tools stuff seems to
run fine with the in-kernel vmware support. Not sure about performance
etc, but it boots, generates no errors and VSphere in the host reports
no issues either.
We might just need an updated open-vm-tools package that only depends on
the in-kernel stuff, and no longer on the -kmod package. I'll try to
followup with the vmware people, as this is getting OT here ;)
--
Tom
prev parent reply other threads:[~2012-02-03 14:11 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-01-27 13:37 [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and 3.2.2 Anthony G. Basile
2012-01-27 16:02 ` "Tóth Attila"
2012-01-27 16:06 ` "Tóth Attila"
2012-01-27 17:38 ` [gentoo-hardened] Please test hardened-sources 2.6.32-r88 and3.2.2 radegand
2012-01-28 5:41 ` Anthony G. Basile
2012-01-28 19:21 ` [gentoo-hardened] " 7v5w7go9ub0o
2012-01-28 18:26 ` pageexec
2012-01-28 20:16 ` 7v5w7go9ub0o
2012-01-28 20:46 ` 7v5w7go9ub0o
2012-01-29 10:38 ` Alex Efros
2012-01-29 17:33 ` 7v5w7go9ub0o
2012-01-28 20:41 ` [gentoo-hardened] " Radek Madej
2012-01-27 18:18 ` [gentoo-hardened] Re: Please test hardened-sources 2.6.32-r88 and 3.2.2 7v5w7go9ub0o
2012-02-02 20:42 ` [gentoo-hardened] " Tom Hendrikx
2012-02-02 20:47 ` Francisco Blas Izquierdo Riera (klondike)
2012-02-03 2:50 ` Brian Kroth
2012-02-03 12:37 ` Tom Hendrikx
2012-02-03 14:11 ` Tom Hendrikx [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4F2BEB18.9090604@whyscream.net \
--to=tom@whyscream.net \
--cc=gentoo-hardened@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox