Conversation

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

apparently some distros still haven’t patched copyfail

love obsession with version number stability

2
0
2

special shoutouts to red hat who sells vulnerable binaries for money

i can understand if community run projects don’t have the best response times but they are literally getting paid for this what is going on

2
0
3

@charlotte on red hat it is even worse that it isn't patch since I'm pretty sure I've seen that there the alternative solution isn't available can't make the module not loadable if it is build into the kernel!

1
0
0

@deetwenty i think you can disable it through boot args but yeah

the mitigation outlined on copy.fail doesn’t work

0
0
1

the fix has been part of mainline for over a month at this point btw :)

2
0
2

I wonder if this could be a potential mitigation too

find /usr \( -perm -u=s \) -o \( -perm -g=s \) -type f -exec chmod go-r {} \+

this removes the read bit from suid and sgid binaries so that the vuln can simply not open these files

0
0
0

@charlotte it is because the disclosure has been a shit show.

1
0
0

@ariadne by the time the vuln was published i was already running a fixed version on all my regular linux systems running community-maintained linux distros.

i am not convinced that red hat, a corporate provider of a paid distribution, was unable to provide a patch in a reasonable time frame despite employing one of the maintainers of the kernel crypto/ tree specifically credited in the af_alg.c file.

2
0
0

@charlotte yes but we didn't have confirmation that we had gotten the fix out already is my point.

0
0
1

@fiore @ariadne fixed versions of 2 stable and 1 LTS release were already out for two weeks at that point.

disclosure was a clusterfuck but like

i don’t think red hat has much of a reason to not have it patched already

1
0
1

@charlotte @ariadne i was just joking about corporate environments ^^

0
0
0

PregNuki Raccoon: Shitposting for 2 (at least!)

@charlotte
Eh, Ubuntu and Manjaro will get to it...

...eventually...

.....maybe in 6 months...?

0
0
0