Re: Linux 3.2.18

From: Willy Tarreau
Date: Mon May 21 2012 - 10:27:50 EST


On Mon, May 21, 2012 at 04:18:40PM +0200, richard -rw- weinberger wrote:
> On Mon, May 21, 2012 at 4:02 PM, Ben Hutchings <ben@xxxxxxxxxxxxxxx> wrote:
> > I'm announcing the release of the 3.2.18 kernel.
> >
> > All users of the 3.2 kernel series should upgrade.
>
> Should or must?
> IOW does it contain security fixes?

"security fixes" is a nebulous concept. I tend to define security issues as
issues that can be triggerred on purpose once known, in other words, issues
whose risk of appearance suddenly changes once they're disclosed.

Based on this, one guy's stability bug is another guy's security issue. If
you're the only account allowed on your servers and a vulnerability allows
any local account to crash your RAID card by reading something in /proc,
this might not be a security issue for you, just an annoying bug. And if
your laptop's WiFi draws all the battery's power when receiving specially
crafted packets, you might consider this an annoying bug while a solar-
powered router operator will probably consider this a critical security
issue.

The best you can do is review the changelog to see whether you're affected
or not by what is fixed there.

Regards,
Willy

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/