Hi!

as you can read in this new bug report that I submitted:

GNU debugger employed via Postfix crashed PaX hardened kernel
https://bugs.gentoo.org/show_bug.cgi?id=541104

also:

GNU debugger checking for PaX and refusing to work with it
https://forums.gentoo.org/viewtopic-t-1011162.html

and:

PAX terminating task on /usr/bin/gdb
http://forums.grsecurity.net/viewtopic.php?f=3&t=4137

In short, from:

https://541104.bugs.gentoo.org/attachment.cgi?id=397334

Feb 23 08:43:51 gbn kernel: [30489.762828] grsec: bruteforce prevention
initiated for the next 30 minutes or until service restarted, stalling
each fork 30 seconds.  Please investigate the crash report for
/usr/bin/gdb[gdb:14515] uid/euid:0/0 gid/egid:0/0, parent
/usr/bin/gdb[gdb:14507] uid/euid:0/0 gid/egid:0/0


but, if Postfix is configured correctly, mail is still sent... but the
scare is ugly...

Surely, the gdb on such kernel does no work at all, other than the scare
on the poor user.

I think it would be a good thing to post a line that reflects this
issue, and warns Grsec-hardened users of it, in the:

http://www.postfix.org/DEBUG_README.html

Cheers!

Miroslav Rovis,
Zagreb, Croatia
www.CroatiaFidelis.hr
-- 
Miroslav Rovis
Zagreb, Croatia
http://www.CroatiaFidelis.hr

Attachment: pgpqZb_yyJr9L.pgp
Description: PGP signature

Reply via email to