[grsec] binutils 2.15.91.0.1 + PaX patch for Debian SID

pageexec at freemail.hu pageexec at freemail.hu
Tue Jul 27 18:15:25 EDT 2004


> I take debian just won't make these changes to to binutils and libc?
> Why not, I wonder.

the binutils changes make sense only if the distro's main kernels
use PaX as well, which is not going to happen anytime soon i guess.
as for libc, they've been aware of it for a few months now. since
upstream had already fixed it even before novsyscall was added to
PaX, debian's glibc will be fixed too as soon as they take the next
glibc cvs snapshot (or backport the few lines of change).

> Are they major changes?

neither are, but PaX (let alone grsec) are and without them the
userland changes are pointless.

> Have you filed bugs against the mainstream packages?

i'm aware of this one only:

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=245563



More information about the grsecurity mailing list