Opened 18 years ago

Closed 18 years ago

#1831 closed task (wontfix)

LFS 6.1.1 contains a root hole in kernel, and maybe other problems

Reported by: alexander@… Owned by: lfs-book@…
Priority: normal Milestone:
Component: Book Version: 6.1.1
Severity: normal Keywords:
Cc:

Description

CVE-2006-3626 (root hole due to /proc race) applies to linux-2.6.11.x. While one can surely backport the patch from linux-2.6.16.25, this is not the best thing we can do. Reason: nobody has audited LFS 6.1.1 for other security problems, and it contains software versions unsupported upstream.

Proposal: on the main page of the LFS part of the web site, say that there is no stable version of LFS now that is recommended for general use.

Change History (1)

comment:1 by bdubbs@…, 18 years ago

Resolution: wontfix
Status: newclosed

LFS 6.2 will moot this ticket. 6.2-pre2 will be release 7/21/06 with the full 6.2 release targeted for 7/25/06.

Note: See TracTickets for help on using tickets.