• [SECURITY] [DSA 3886-2] linux regression update

    From Salvatore Bonaccorso@1:229/2 to All on Tue Jun 27 21:40:02 2017
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-3886-2 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso
    June 27, 2017 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : linux
    Debian Bug : 865303

    The security update announced as DSA-3886-1 caused regressions for some applications using Java - including jsvc, LibreOffice and Scilab - due
    to the fix for CVE-2017-1000364. Updated packages are now available to
    correct this issue. For reference, the relevant part of the original
    advisory text follows.

    CVE-2017-1000364

    The Qualys Research Labs discovered that the size of the stack guard
    page is not sufficiently large. The stack-pointer can jump over the
    guard-page and moving from the stack into another memory region
    without accessing the guard-page. In this case no page-fault
    exception is raised and the stack extends into the other memory
    region. An attacker can exploit this flaw for privilege escalation.

    The default stack gap protection is set to 256 pages and can be
    configured via the stack_guard_gap kernel parameter on the kernel
    command line.

    Further details can be found at
    https://www.qualys.com/2017/06/19/stack-clash/stack-clash.txt

    For the oldstable distribution (jessie), this problem has been fixed
    in version 3.16.43-2+deb8u2.

    For the stable distribution (stretch), this problem has been fixed in
    version 4.9.30-2+deb9u2.

    We recommend that you upgrade your linux packages.

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: [email protected]
    -----BEGIN PGP SIGNATURE-----

    iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAllSsjxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Q7Bw//Sdd+3lkJjSOUvuFOVpyrXR6zGgCW4+iQEDkTtfit5NZ5Uwa+89gQ3akJ CRvYJ55aCVc/LCrBpxaGhI0lb8kUSK4dLFTPnC+zm5SJF4XbXCCYhS3+UAC85Imo ElRMySUDEmbHLsnUvdcWAjcBmgV06asT2Ia+QsaGajLMf/+5reDI1D/MNXb8AI8M mnCgSOIlSy4neZTxKwmyYHtdMfrKMTYbXMG9zUfrM7jsOfbn6KvsaPWTdP1+5EBO lPrHrNkVzA8VUrO9sje82/kLpfl4cYPYlEoQfaXQUogrKuvMkJ0gOn858OqdD038 nbItnvdcmbHsFMckhykOOheL3Iin3QxOWHBK93MZCZseubNAphrkqFV5+omki5eD +M1UkvR15dPBilub0l+a8cVUIO2TY2yJSSaDZgTEPepuyTbOxCc0hvwNoqdG0hH6 gD6edfWJ1TNiDVD1pW9SGRF0QIf+HyoKhEVGyuJfJQtRe4hdgCcKxu2VAGbpdqul qIlu4UaQhzclx4P2urIRR+HRMX6K61IAj3mxuItUkP+Xa+xxTby2soGRH6Q9IMHc iqgdYZmmWe3gc21I8BaKclefDP8tNJgHiLr7j+CwQawzuj3lWHJ9ZmXx0EfU1VJT ZYbZthQ7XChu5fI6uRfmGWMocE3700HzQDtb6/NFRnsElxlx5L4=
    =VAqb
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)