2 ms·
It seems that Linux distros are now releasing fixes: - Debian is prevalently not vulnerable: https://security-tracker.debian.org/tracker/CVE-2016-7117 https://
by HerrMonnezza 10y ago
It seems that Linux distros are now releasing fixes:
- Debian is prevalently not vulnerable: https://security-tracker.debian.org/tracker/CVE-2016-7117 https://security-tracker.debian.org/tracker/CVE-2016-7117 (except the "oldstable" release)
- for Ubuntu, the situation is more complicated, as it depends on the actual kernel package installed: https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7117.html https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2... For the "linux" kernel package (prob the most common), the situation looks like this at the moment::
Upstream: released (4.6~rc1)
Ubuntu 12.04 LTS (Precise Pangolin): needed
Ubuntu 14.04 LTS (Trusty Tahr): released (3.13.0-86.130)
Ubuntu Touch 15.04: DNE
Ubuntu Core 15.04: pending (3.19.0-59.65)
Ubuntu 16.04 LTS (Xenial Xerus): released (4.4.0-22.39)
Ubuntu 16.10 (Yakkety Yak): not-affected (4.4.0-22.39)
- for CentOS/RHEL, my understanding is that fixed kernels have not yet been released: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7117 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-7117