5 ms·
Well, with micropatching you don't need to reboot and you only have to review minimum code changes - and if the patch is not working for you you can unpatch it
by sst8 10y ago
Well, with micropatching you don't need to reboot and you only have to review minimum code changes - and if the patch is not working for you you can unpatch it (with proper permissions, ofcourse).
- j_s 10y agoPretty sure this specific example would require a reboot, changing a Windows kernel DLL. There seems to be some confusion over whether or not the 0patch tool can update the kernel without a reboot, though. https://news.ycombinator.com/item?id=13775550 https://news.ycombinator.com/item?id=13775550 Patching a user mode app/dll would not require a reboot, just a restart of the app.
- johntb86 10y agoI believe this code is in gdi32.dll and is one of the few pieces of GDI implemented in user mode. However you'd probably still need to reboot because almost every program in windows is linked with it and would need to be restarted.
- dielel 10y agoHi, Stanka from 0patch here. If you want to enable or disable (aka "patch" or "unpatch" the application) you don't need do restart the application. Not even if your app is running and you've just install 0patch agent. This is how it is designed to work in user space. When the official MS patch is installed (hopefully with the fix) this particular 0patch won't apply anymore. As we try to make 0patch agent robust and reliable we don't support kernel mode at this moment - we will make this step slow and with great caution.
- j_s 10y agoCan you please clarify whether or not this specific patch is user mode or kernel mode? @johntb86 mentioned GDI is split and this is the user mode part.
- dielel 10y agoOur micropatch (7 of them, really, for 4 different Windows OS versions) for CVE-2017-0038 is user-mode. As are currently all our micropatches. Processes using gdi32.dll do not need to be relaunched to have it applied.