Skip to content
This repository was archived by the owner on Oct 11, 2023. It is now read-only.
This repository was archived by the owner on Oct 11, 2023. It is now read-only.

Look into and deal with CVE-2017-1000364 & CVE-2017-1000366 #1932

@SvenDowideit

Description

@SvenDowideit

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000364 & http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-1000366

for buildroot - https://git.busybox.net/buildroot/commit/?id=d29c7196bf5e610123dcc697197d4013d5869f68

  • kernel patch for guard page size (using 3.9.33 plus patches from deb9u2) for v1.0.3-pre1
  • add BR2_SSP_ALL=y and BR2_TOOLCHAIN_BUILDROOT_GLIBC=y to amd64
  • add BR2_SSP_ALL=y and BR2_TOOLCHAIN_BUILDROOT_GLIBC=y to arm
  • add BR2_SSP_ALL=y and BR2_TOOLCHAIN_BUILDROOT_GLIBC=y to arm64
  • watch for SSP fix for gcc
  • see if adding SSP slows things down noticably

The 1.0.3 release is also going to update the os-base tools to on all 3 arch's to Buildroot to v2017.02.3-1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions