Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Kernel & Hardware
  • Search

StackRot (CVE-2023-3269) - which kernel to run?

Kernel not recognizing your hardware? Problems with power management or PCMCIA? What hardware is compatible with Gentoo? See here. (Only for kernels supported by Gentoo.)
Post Reply
Advanced search
5 posts • Page 1 of 1
Author
Message
jmbreuer
n00b
n00b
Posts: 26
Joined: Wed Sep 07, 2011 9:22 am
Contact:
Contact jmbreuer
Website

StackRot (CVE-2023-3269) - which kernel to run?

  • Quote

Post by jmbreuer » Fri Jul 07, 2023 7:38 am

I've become aware of the StackRot vulnerability https://github.com/lrh2000/StackRot in recent Linux kernels.

Current stable (on amd64) is gentoo-sources-6.1.31, which I very much presume does not contain a fix for CVE-2023-3269.

Is there an effort already underway to have a sufficiently newer kernel stabilized imminently? Where would I find information about such gentoo security efforts?

The GLSAs https://security.gentoo.org/glsa/ currently seem to end in May 2023...
Top
Goverp
Advocate
Advocate
User avatar
Posts: 2402
Joined: Wed Mar 07, 2007 6:41 pm

  • Quote

Post by Goverp » Fri Jul 07, 2023 7:56 am

I'm not sure I'd panic yet. As the article says:
... Consequently, exploiting this vulnerability is considered challenging.
To the best of my knowledge, there are currently no publicly available exploits targeting use-after-free-by-RCU (UAFBR) bugs. ...
And if you are desperate, you simply use a pre 6.1 kernel, such as 5.15.120, the current most recent long-term stable, available in both gentoo-sources and gentoo-kernel{,-bin}
Greybeard
Top
pietinger
Administrator
Administrator
Posts: 6620
Joined: Tue Oct 17, 2006 5:11 pm
Location: Bavaria

  • Quote

Post by pietinger » Fri Jul 07, 2023 9:01 am

I am sure our recent gentoo-sources 6.1.38 will become stable very soon. If you cant wait you might install gentoo-sources according Option 3 (as I always do; I am already on 6.1.37):
https://wiki.gentoo.org/wiki/User:Pieti ... LTS_series
Top
jmbreuer
n00b
n00b
Posts: 26
Joined: Wed Sep 07, 2011 9:22 am
Contact:
Contact jmbreuer
Website

  • Quote

Post by jmbreuer » Fri Jul 07, 2023 2:37 pm

Thank you for the suggestions!

I'll pick a suitable kernel from 5.15.<recent> or 6.1.38~amd64 for now.
Top
pietinger
Administrator
Administrator
Posts: 6620
Joined: Tue Oct 17, 2006 5:11 pm
Location: Bavaria

  • Quote

Post by pietinger » Sat Jul 08, 2023 10:55 am

6.1.38 is stable now ! :D
Top
Post Reply

5 posts • Page 1 of 1

Return to “Kernel & Hardware”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic