LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

How far back?

Posted Dec 3, 2003 0:15 UTC (Wed) by pblanco (guest, #16087)
In reply to: How far back? by ncm
Parent article: The brk() vulnerability

It's interesting that my SuSE 9.0 with the 2.4.21-144 kernel has the patch. The article implied that 2.4.22 and 2.4.23 had the patch, so I assumed that earlier releases wouldn't have it. What gives?


(Log in to post comments)

How far back?

Posted Dec 3, 2003 3:17 UTC (Wed) by Mithrandir (subscriber, #3031) [Link]

SuSE have applied 144 patches to that kernel, so it could hardly be called a vanilla 2.4.21. I'd be guessing that they applied the patch as a routine security patch at the time that it was released for 2.4.23-pre.

How far back?

Posted Dec 11, 2003 6:59 UTC (Thu) by wildpossum (guest, #17744) [Link]

No that is not implied. What SUSE (and other vendors) do is patch the kernel that was released with that box version, rather than risk breaking things by upping the kernel version without adequate testing. So the bug was in the 9.0's 2.4.21 kernel, SUSE patched it when the alarm went out, and you got this update when you ran the YaST Online Update tool.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.