← Back to team overview

registry team mailing list archive

[Bug 293000] Re: hardy: openssh-server oom_adj can lead to denial of service

 

Is there going to be a back port to Hardy 8.04 LTS?

I have had a serious issue with a Virtual Server where the only access
is via SSHD. This resulted in an errant CPAN update downing the entire
box due to all services started via SSH being oom_adj == -17 and
therefore not being killed when out of control.

I cannot risk setting SSHD_OOM_ADJUST=0 in /etc/default/ssh as it is
essential that sshd remains running at all cost.

I have temporarily put echo "0" > /proc/self/oom_adj in /etc/bash.bashrc
as a workaround. At least this may stop some potential problems.

This is serious in a Virtual Server environment, where RAM is typically
low and remote access requirement high.

-- 
hardy: openssh-server oom_adj can lead to denial of service
https://bugs.launchpad.net/bugs/293000
You received this bug notification because you are a member of Registry
Administrators, which is the registrant for Debian.