From 6957ff517792454038751c64e1058442af1086db Mon Sep 17 00:00:00 2001 From: Tom Wijsman Date: Wed, 25 Sep 2013 17:40:51 +0000 Subject: Revision bump for 3.10.7. Fixed an important buffer overflow in add_page_map() causing kernel panics, backported from 3.10.8; reported by stintel on IRC. Fixed PID Spoofing Privilege Escalation, backported from 3.11, see bug #483614; CVE-2013-4300. Fixed multiple HID security flaws, backported from GregKH's stable queue and Linus' master, see bug #482896; from CVE-2013-2888 till CVE-2013-2899. Users that had kernel panics due to buffer overflows or need additional security are suggested to update. Package-Manager: portage-HEAD/cvs/Linux x86_64 RepoMan-Options: --force Manifest-Sign-Key: 0x6D34E57D --- sys-kernel/gentoo-sources/ChangeLog | 13 +++++++- sys-kernel/gentoo-sources/Manifest | 19 ++++++----- .../gentoo-sources/gentoo-sources-3.10.7-r1.ebuild | 39 ++++++++++++++++++++++ 3 files changed, 62 insertions(+), 9 deletions(-) create mode 100644 sys-kernel/gentoo-sources/gentoo-sources-3.10.7-r1.ebuild (limited to 'sys-kernel') diff --git a/sys-kernel/gentoo-sources/ChangeLog b/sys-kernel/gentoo-sources/ChangeLog index 0a3a422b8590..89cf2a94c69e 100644 --- a/sys-kernel/gentoo-sources/ChangeLog +++ b/sys-kernel/gentoo-sources/ChangeLog @@ -1,6 +1,17 @@ # ChangeLog for sys-kernel/gentoo-sources # Copyright 1999-2013 Gentoo Foundation; Distributed under the GPL v2 -# $Header: /var/cvsroot/gentoo-x86/sys-kernel/gentoo-sources/ChangeLog,v 1.1189 2013/09/15 10:18:36 tomwij Exp $ +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/gentoo-sources/ChangeLog,v 1.1190 2013/09/25 17:40:46 tomwij Exp $ + +*gentoo-sources-3.10.7-r1 (25 Sep 2013) + + 25 Sep 2013; Tom Wijsman +gentoo-sources-3.10.7-r1.ebuild: + Revision bump for 3.10.7. Fixed an important buffer overflow in add_page_map() + causing kernel panics, backported from 3.10.8; reported by stintel on IRC. + Fixed PID Spoofing Privilege Escalation, backported from 3.11, see bug + #483614; CVE-2013-4300. Fixed multiple HID security flaws, backported from + GregKH's stable queue and Linus' master, see bug #482896; from CVE-2013-2888 + till CVE-2013-2899. Users that had kernel panics due to buffer overflows or + need additional security are suggested to update. *gentoo-sources-3.4.62 (15 Sep 2013) *gentoo-sources-3.11.1 (15 Sep 2013) diff --git a/sys-kernel/gentoo-sources/Manifest b/sys-kernel/gentoo-sources/Manifest index 161aaa9e2647..546db67b2dd5 100644 --- a/sys-kernel/gentoo-sources/Manifest +++ b/sys-kernel/gentoo-sources/Manifest @@ -41,6 +41,8 @@ DIST genpatches-3.10-18.extras.tar.xz 17752 SHA256 0cee08fb7ebb857d78741b833190d DIST genpatches-3.10-19.base.tar.xz 229396 SHA256 d89a5eefd37a777c310698921723130b00ac0149804aa6653cbc90eef6d97179 SHA512 0c6615c2279d1e7e9bc8ecaaed3336b672cb66bb738c9b017700ea06d9d37e5f735ff0355d0394498a51647bc1516e8da97be953a5250aded32c31e96b9a314c WHIRLPOOL 983bcee3c1d2fa35de39828adcb929c846a2c472a2d03ef27f3cffd8c5481ae81437f21b05268781d4d2045d78f2ada5c3e55b21f0beb3bbe997e0db8b869bfb DIST genpatches-3.10-19.experimental.tar.xz 45588 SHA256 a10cdac1f5fd22d1d81a2f35bac9927028f7545a681f789c88638765aea4c983 SHA512 302de0d2dbfb2325084f2fad611a2b452b17cf07da88378b97a163c2de2879862b020be861167ce9e165ce11d9bac55a13bb9e9c0b1627f5a50445b2fb423ec8 WHIRLPOOL ba3d4258e886b8007871fa80dfc1308813bde8cf7e4a492df0dc01dc102298fd48b507aa576189f18de98db9fb641c729bac14c8d9126b44fe6c5e8ec7803cf7 DIST genpatches-3.10-19.extras.tar.xz 17752 SHA256 0cee08fb7ebb857d78741b833190d3829e974231de177918f89cbf32e194252b SHA512 0fab063d4d69f3ad824cf573f4da839d635f1f473af928c85544df60bb62e9cd29ca67f95110689299e79bc9f5b35455436c53fbc732569170b5decf17f74e97 WHIRLPOOL 9a73aa0e84690820832791b63749e01f4d622cf1f0327ae33a6188b866ba1459f6f6b3a01d31412fa3cc226da8af6ab63ee59db29cdfb787cd24901c85b84233 +DIST genpatches-3.10.7-1.base.tar.xz 226708 SHA256 2c0aeb406bc461db705155b7740306527f2685f533a1f1d0ddcfa55b728ea906 SHA512 af4b7f9ae6f66597bb8216c102befcdc9513b954f92009e0dd4ebd48f21c7d71510b27b59575ad6dedd976a4d92cbbe090bef75fcb64ddd7089b03103f4cc45f WHIRLPOOL 287e2eafd279549d120ef6c7a8235c08d29b529f042f6cb779064b0488e3e93812a7a9ae12bebef42a7055b0fcfb156c90ffcc55b957ad53a135cda1cc3a02d8 +DIST genpatches-3.10.7-1.extras.tar.xz 17732 SHA256 699d67f6827c9c06207bdcd81ff7132efe148c49f9088ad70c2354bc1aed4440 SHA512 4445126ae7662fae576e46ca9728895311f6956de95efc38d0ac4499d3b8973092a4fa42af2dbf63e136168636b1c5b49d6db215e13c57cf603a65e0a3f90f4d WHIRLPOOL 1b792770c9a45102bcbb626193d10e35fca350227aed7b76cc47a3460a9fbaea9383659b2665855120aea30e8509aa5818a22231732587922950aae56f2e97cc DIST genpatches-3.11-3.base.tar.xz 7472 SHA256 262db0950ce868111fcbb0e9575b01967ead9a8a842109fec7949ac6d2037126 SHA512 161873e8c2c62ed974fb3bc97cd8377184692f853dff13d0bca4f2c0662ace3c05c6bf168a76c7a106303d612a8a90dd4ce4e944da6a0ed83adefb2b110b664c WHIRLPOOL df231f1e8f9360f009de89ab9b466a929c597bb6138575205f892dc4d49adf0f6df2586d633e89d95bdba42fa94d2d2bfeb1e51adfedc5eb31b73e096f45549c DIST genpatches-3.11-3.experimental.tar.xz 45276 SHA256 0f2297d5ae40c532ec823ca95de977e55bfd9adef076a91564def0e876a31d0f SHA512 3098f9e6ad8a41389307dafe5674f1680c7169f031c951dcd8acbf02432a632e5de149059893daeb024847bb1bf63f5cd07ae7302c63bdc3934e47e9518c97ef WHIRLPOOL 139068f19f16143be570d7341f892b271e4005aef8dabd7b488ca6322cab252c9d3d21c77f932bc638b3a95a8ce9b8d1baaa898d268400881d9add464f324a46 DIST genpatches-3.11-3.extras.tar.xz 16644 SHA256 7039fea3cac3eb3a9e7468d0db479d1f4e8ab0a08779cdcc9bae5db06cb6f0e1 SHA512 f9b80a5e07a5dc7201aa2d5d92140a885564fed880d6167400830fc9c0d1bf667a1c549c3f06d446254c504d62ccea36332da49cc2ca47d343c61e35e85523fa WHIRLPOOL fd42b19839128515f63771977702a522b46751b6ead85ace649a816106f24c547596c8c269732c83fc3385bc5d24a93d8d79cb4b3664f108be4b4327af216013 @@ -83,6 +85,7 @@ EBUILD gentoo-sources-3.0.96.ebuild 860 SHA256 6b0697fc3f91147da089702bece1f614a EBUILD gentoo-sources-3.10.10.ebuild 867 SHA256 9b67a8067e6dfa1200b7989a93692459699b269a966e2ab71219617bd2757e35 SHA512 dfc2eeb41c4aee7e562b00e69fb2cac84ba25de6b20e8243e0d1f358df7840ad0be2bc34f7df84e7ed9540756a8ea8441426ede1ba22fbcc80e65bb33f57438d WHIRLPOOL afb03cc05dff8b4d6fe035e7f2fee1766d4b8af76e28540eaa451b1a1c2e5580440a52d796eea1ae728a6b786bee6bccebb48bc75ba5516db888281b3a6a2a17 EBUILD gentoo-sources-3.10.11.ebuild 893 SHA256 fdc1e6f54d89bb0950a832513972e4766825c7c1931ff3a11cb9234ce5a9b531 SHA512 463f2a590108a7c0166d5d9345980fd315d68a51cade6b42d01e50dfb46d87e9a92c2a31c540a30e36b34cabd9752fa4e3578a4e3e95ccba3d2ac474bf22155f WHIRLPOOL 3f11e1e16e114490b65f3d8d4fbbbe261f481311bf759c0173a41e55af2690485b841fddaa56662633ae1e20cbef265a19666aeec95c68a5e6bf5230f47cb536 EBUILD gentoo-sources-3.10.12.ebuild 893 SHA256 e197254c4ee979b35d64d23c16a8041c1fc8f4e10b8fa414c25096eb7581b57d SHA512 6c3cbe05ebc0fd7caf8f15fc22d1e61822054fd376b2cc954241b77e859d4b440340475de512d4906df7d7c9515d916fe3ef118e82feb888fbfe3b6fc7973172 WHIRLPOOL fb4c5da0824dc28243054fe4cd4e01d4aac37f463be15aa06edc95572535c658180f92e88f83d0fb72290fa0a901cd074e7f7e88fa593c29880e636e7993d848 +EBUILD gentoo-sources-3.10.7-r1.ebuild 1049 SHA256 63675222d720ded02e3b0448a14fdef7f0db7d795ba0830714eae526b61e8a59 SHA512 8e6e0b5b38823513444f83de7279eed341e81a2de6c1b84ed1f98bc4a515aa2368af31680d895d6ba99e41bef6bcad84b9d5a4736a760d14426c9ca916fdf476 WHIRLPOOL 458c8ca0ede25a995949bfcf84e5de47ee0144ca62a28e024ac7ca24345e3617715f54192157f0b915b81ce085b16a5bec972137b657285abdf935b5616b60ee EBUILD gentoo-sources-3.10.7.ebuild 856 SHA256 7999ad0f9274d769d3784eb261752188b81bdf3b99f18ad06ab14345ec0bb77d SHA512 80a00bcb0a82211527f6ae583f2ce0903defdffd2ab1bdbcc0443ac51b02f91bdd7455b8971eaaa81ef736d904a8b7330b508760bd696d26e68d415b94b240a5 WHIRLPOOL 26156ff3a3e4ce9dcf768f25a78f3a5b821f36da2de236c5381bc8086a828b7e2befd0142b8f9ce554dd14a2b29c2e8162b7f9a4e09382ddb338bc3366141978 EBUILD gentoo-sources-3.10.8.ebuild 866 SHA256 00115a86b4d32d7f6dd98d2519e6d1da4b37de6c7a5065c3a45bcd1ca77d9329 SHA512 e1fedef16a62720c5c71c818f684fbe7dc375fc8f093b27a06ef6bfe2775d7591a360db241b1586a269cb785b84f6952d2f38e0acd6c93f4487b8be4e9bf4539 WHIRLPOOL 349c0245a1e7588e08b115b6bc51c9d552e3784db540a57a6f15446389779d2a8e81c6130f2b28abce8fdbd766ed6edfb43bf9c2ba342a622e2c35801e5125be EBUILD gentoo-sources-3.10.9.ebuild 866 SHA256 be36933077138fabf0bc544de6e2d75717f31920ce95937b730b5fceba9cc59e SHA512 574c7d7167a01f1dbb03104209ff276da049d073f1ed73d9f28a8c180df9ef898f8306b9f106f1d92cdebc15fc127d710ee5b929edbd5d4c8f63d17da1404540 WHIRLPOOL 9c50aee33fa7b20c2584c9e5cc9414d61f9967fce8fe3a5176d6828715eb6d1068b0a6df9729f6dbab4baed0870ff969e31a84a5be6277a6470f0b25e8dae925 @@ -98,18 +101,18 @@ EBUILD gentoo-sources-3.4.61.ebuild 860 SHA256 5d6ade58dd6f4c4e8de673fbe45836cab EBUILD gentoo-sources-3.4.62.ebuild 860 SHA256 8c65689a1fdadb42ee61a047652ba0e53b457bccee5d1284e264aa50dd848b72 SHA512 7250aaefcde24c306468df84e7f543d2f7d3799e4e5371f26f8813954fe5fff82f0b3c89adbc0a6702857c48778f769dba84dd97b1e2b489bf6f1b4aefd9f364 WHIRLPOOL c7cc1153e7d4c9b263fbccafb77ae47d85c5f321d4018fa36b64aa862f9815bba0121b845eba699e0bde5b6a11506e72b4d598b81d44701ab54132cb05d27254 EBUILD gentoo-sources-3.8.13.ebuild 846 SHA256 33d2ce69f65cc6582c77554c85971c92f820fff7fc3529539ff9e805bb6892f9 SHA512 de12c02af36d26099b9fdf4ee5d6fde214c984d8582008f448362c71754c1086efca3a00a8a61b5465380128495b0d650dae72b01222e8b6d05b655134923206 WHIRLPOOL e291507896cc4dd530752179b9d603e3bd7e283c4e81f44a28b6c0f573fce6cedf98f6fa6f31259126f0de979b0edcd23e3e5de4d877083be0fc2e09c4fd4904 EBUILD gentoo-sources-3.9.11-r1.ebuild 821 SHA256 e2fccbce658603a2b5528c4d291afe3a799fe79c648d34a11a553d12387d20d9 SHA512 a10826404e9845ed7843b6ed62ed387a2ea546e0abd152bc0722eeb6749b5c3c1ca687ddd9bb09897b240cd7217c20196d2ecc20a0d96fd0ba42fd8ad934f82e WHIRLPOOL 5f2dea7fc17408fca040ea7e7de8451c30984207f8194872bbde16b5c65f8cb3a2ad73e0fce60c248c8b387c36600b947e1921f66db599936e75a51a84835887 -MISC ChangeLog 37263 SHA256 96ab279a0984e66e949b4ae936d4cdba9a7fb419f1c85e7e0ecc538a249cf2ad SHA512 0b4139c60583a947d4c3fe920a760192d11823a0782d5be0894d5cc5ab0ad7850712b2d2f251ff3b6b61f912d0068c68bea59ef0a17195170557eb16e3c2cad2 WHIRLPOOL 03ebe1703809c6aed50cb7437939a58bb745f7f8e9295f4ae194336b8a8fa8415cd5fc68c129d780039176401169404bcc06b49891927617f2a6a3c33dd460b0 +MISC ChangeLog 37903 SHA256 dff541a6d2e0940c750f65a25949ea4eee1f5eb8b3e41967709c828bd6a77122 SHA512 f046e31027b06e1c598c5678777cf5bac82239e0e136f70e6d24ab505bf5e68a06cdacf4ccf6c70f75a09faff1308c8c1910d1636f6ce52da2944e51ec9bcefd WHIRLPOOL 7ba44aa562d8ba6798d20d20a2f7c99e6a166d6f8174c8bca5d1b18b504561328237d007755d185b5e108ca3b164d7e1a288c7da4c87eca3cf9c17c59cb01469 MISC ChangeLog-2007 91971 SHA256 8c37498df2246749abb2fd1eca05c396257989b91ba5ec0f83cedb25488118a9 SHA512 2215a9856bc1706abe21ad51d0af6176fec226e85a56ad8f54664d20a041bbe076359347f473a87c47904df2d8d2006d56d1535528b2eb7aa756f96ad9554876 WHIRLPOOL dd881fa7bbfc42ca35a46a0fe01d751b3373ac8f4e2ce5626ff26f94244d729e107f57b1be43daf3b73c2f18b090ee896d8a5eb38888fa9ca01097d1cbd46da7 MISC ChangeLog-2012 101665 SHA256 a60304f93fc4644cdf0b068e586f6036d4463ea4b21bd745a8aa926da71db6ec SHA512 892085806f4c87f64db78e04d3c215ae6bca8939ffeced8a3792fe4a2476e72d2cc9dbc8a3b906943971eb853c337847e6a8bf976f9496be9944e216fb983234 WHIRLPOOL 590f17b5a90f48fa1733959500ce06fd72f95524b64b6abf508653a616961af2c0ea04ca2dbfe5523ff9dcd3bc67b3b24bc368eb84326d091ca449e558555f46 MISC metadata.xml 512 SHA256 80143273f4462ac67194f8ef90706e5ebf65f3f30ff153b7ee19d2c155f49f7b SHA512 6262ba3cbc6480081a195024fc752ad0df27afe9b71d626d759f747a52a2a181d114379e463bd8741a843622556c1e46820e535e8fbe71e2790828370d70c5f0 WHIRLPOOL b4430c0590efa2c5cbfc85fed1386943f4c8d101dfc07a76ba79c37b1fe2fe4db21f65b58186e1cad1ea3987292c2ea0251f0e2017be018c020f7e2309b57bd1 -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.21 (GNU/Linux) -iQEcBAEBCAAGBQJSNYhZAAoJEJWyH81tNOV9bgYIAKxOqo66G1XI+Nnj/6D1XOik -NT+4oyAa6mMSb1QfApCH6QgbRxZEUvUkkkAdzHif/jLqBJwmZZ6+yRsx+JdPS3JW -lRXifDbG8sgEH05UraKM119ov+Z78PEjD2qXLhAh19fbK1L8nD2UbBYrG0tOYWls -9c5IykHFx26e9PoCLWcb+gVFgVrBMbmWBXOIHLZqowpKvMCLWgUorRF6T0uksgXf -0T6OBkFzhUo3tfN6Nb5ekMqC9WX823IssaXWbMZi/NF5VKf9JKrR83+3ca7qD72+ -TX0tUoxZMxgsFTMyaCBGNkT9VIWx805rzm0+faISjlWuQSxazOLZx2xDohhH/wc= -=kkgU +iQEcBAEBCAAGBQJSQx7nAAoJEJWyH81tNOV9ybEIAJGcNJ/Ex7IowGAV4Rsatrgd +YaqWp9K5vMyWnkuQg229jE9kYkviB9LxWops9RLyEmPPAeXVaD36l6uu5lK7dLcV +X2rM2QJHkebe1kXclXAVefroU4xY2G2P+LhnARMAeAkOIY9uiNJWswuHof9X0fM4 +Z62xX2Qjvrap4UvGb4lKhatEO5uRYGxJFJTuBVL5PqUUC5mT/QcwzR82/lg3vNGa +/azGCJ/lST2p0df1XyzaRZy3hnTTkMbkHuIVnLlEdfe6ZOoTzvznidu7FI+9Ejok +NhOYLLoWl83Argbi6C9B/PxLprUFGpO5zDyKd7lBgHReEuHrjlcZtGqvHHyoLZs= +=GsGj -----END PGP SIGNATURE----- diff --git a/sys-kernel/gentoo-sources/gentoo-sources-3.10.7-r1.ebuild b/sys-kernel/gentoo-sources/gentoo-sources-3.10.7-r1.ebuild new file mode 100644 index 000000000000..e6cdb90e97f7 --- /dev/null +++ b/sys-kernel/gentoo-sources/gentoo-sources-3.10.7-r1.ebuild @@ -0,0 +1,39 @@ +# Copyright 1999-2013 Gentoo Foundation +# Distributed under the terms of the GNU General Public License v2 +# $Header: /var/cvsroot/gentoo-x86/sys-kernel/gentoo-sources/gentoo-sources-3.10.7-r1.ebuild,v 1.1 2013/09/25 17:40:46 tomwij Exp $ + +EAPI="5" +ETYPE="sources" +K_GENPATCHES_VER="1" +K_DEBLOB_AVAILABLE="1" +inherit kernel-2 +detect_version +detect_arch + +KEYWORDS="alpha amd64 arm hppa ia64 ~mips ppc ppc64 s390 sh sparc x86" +HOMEPAGE="http://dev.gentoo.org/~mpagano/genpatches" +IUSE="deblob" + +DESCRIPTION="Full sources including the Gentoo patchset for the ${KV_MAJOR}.${KV_MINOR} kernel tree" + +GENPATCH_PREFIX="genpatches-${PV}-${K_GENPATCHES_VER}" + +SRC_URI=" + ${KERNEL_URI} + mirror://gentoo/${GENPATCH_PREFIX}.base.tar.xz + mirror://gentoo/${GENPATCH_PREFIX}.extras.tar.xz + ${ARCH_URI}" + +UNIPATCH_LIST=" + ${GENPATCH_PREFIX}.base.tar.xz + ${GENPATCH_PREFIX}.extras.tar.xz" + +pkg_postinst() { + kernel-2_pkg_postinst + einfo "For more info on this patchset, and how to report problems, see:" + einfo "${HOMEPAGE}" +} + +pkg_postrm() { + kernel-2_pkg_postrm +} -- cgit v1.2.3-65-gdbad