GNU bug report logs -
#27429
Stack clash (CVE-2017-1000366 etc)
Previous Next
Reported by: Leo Famulari <leo <at> famulari.name>
Date: Mon, 19 Jun 2017 22:27:01 UTC
Severity: serious
Done: Leo Famulari <leo <at> famulari.name>
Bug is archived. No further changes may be made.
Full log
Message #61 received at 27429 <at> debbugs.gnu.org (full text, mbox):
[Message part 1 (text/plain, inline)]
On Fri, Jun 23, 2017 at 02:36:41PM -0400, Mark H Weaver wrote:
> Most packages are linked with 'glibc-final' in (gnu packages
> commencement), and we should expect them to now be linked with *its*
> replacement. Try this to find the expected glibc-final replacement:
>
> ./pre-inst-env guix build -e '((@@ (guix packages) package-replacement) (@@ (gnu packages commencement) glibc-final))'
Thank you for the clarification. Indeed, with Efraim's latest patch,
packages seem to be referring to the replacement for glibc-final.
So, do we think this patch is ready to apply? AFAIK, nobody has yet
tried upgrading a GuixSD system with this patch. I won't have access to
my bare-metal GuixSD system for the next few days.
> > By the way, Qualys will probably begin publishing their exploits on
> > Tuesday [0]:
>
> Thanks for the heads-up, and more generally to your prolific
> contributions to security in Guix!
Thank you for your advice and guidance, and to Efraim for taking the
lead on fixing this bug!
[signature.asc (application/pgp-signature, inline)]
This bug report was last modified 7 years and 309 days ago.
Previous Next
GNU bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson.