← Back to team overview

group.of.nepali.translators team mailing list archive

[Bug 1843327] Re: vmlinuz is world-readable

 

This bug was fixed in the package linux-signed-hwe -
4.15.0-74.83~16.04.1

---------------
linux-signed-hwe (4.15.0-74.83~16.04.1) xenial; urgency=medium

  * Master version: 4.15.0-74.83~16.04.1

linux-signed-hwe (4.15.0-73.82~16.04.1) xenial; urgency=medium

  * Master version: 4.15.0-73.82~16.04.1

  * vmlinuz is world-readable (LP: #1843327)
    - fix vmlinuz-* permissions for opal signed kernels

 -- Khalid Elmously <khalid.elmously@xxxxxxxxxxxxx>  Tue, 17 Dec 2019
23:49:07 -0500

** Changed in: linux-signed-hwe (Ubuntu Xenial)
       Status: Fix Committed => Fix Released

-- 
You received this bug notification because you are a member of नेपाली
भाषा समायोजकहरुको समूह, which is subscribed to Xenial.
Matching subscriptions: Ubuntu 16.04 Bugs
https://bugs.launchpad.net/bugs/1843327

Title:
  vmlinuz is world-readable

Status in linux-signed package in Ubuntu:
  Fix Released
Status in linux-signed-hwe package in Ubuntu:
  Fix Released
Status in linux-signed source package in Xenial:
  Invalid
Status in linux-signed-hwe source package in Xenial:
  Fix Released
Status in linux-signed source package in Bionic:
  Fix Released
Status in linux-signed-hwe source package in Bionic:
  Fix Committed
Status in linux-signed source package in Disco:
  Fix Released
Status in linux-signed-hwe source package in Disco:
  Invalid

Bug description:
  [Impact]
  ppc64el vmlinuz is world-readable, possibly impacting security on that platform.

  [Test case]
  Verify vmlinuz is not world-readable after the fix.

  [Regression potential]
  File permissions may be wrong, possibly allowing attack.

  
  --------------------------------------------------------------------------

    ======================================================================
    FAIL: test_096_boot_symbols_unreadable (__main__.KernelSecurityTest)
    kernel addresses in /boot are not world readable
    ----------------------------------------------------------------------
    Traceback (most recent call last):
      File "./test-kernel-security.py", line 1438, in test_096_boot_symbols_unreadable
        self.assertEqual(os.stat(name).st_mode & mask, expected, '%s is world readable' % (name))
    AssertionError: /boot/vmlinux-4.15.0-62-generic is world readable
    
    ----------------------------------------------------------------------
    Ran 125 tests in 31.183s
    
    FAILED (failures=1)

  This currently affects ppc64el.

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux-signed/+bug/1843327/+subscriptions