Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Wed, 3 Apr 2019 22:37:39 +0100
From: Paweł Krawczyk <pawel.krawczyk@...h.com>
To: lkrg-users@...ts.openwall.com
Subject: Whitelisting LivePatch

I'm hitting this false positive quite frequently and I was just
wondering if there is any way to modify p_lkrg to whitelist this type of
changes? What Canonical LivePatch does is, well, essentially patch the
living kernel which obviously changes the code signature. LivePatch
works through a kernel module called lkp_Ubuntu_4_15_0_45_48_generic_49
(or similar).


Apr  2 11:58:43 otto kernel: [3675742.580321] livepatch: enabling patch
'lkp_Ubuntu_4_15_0_45_48_generic_49'
Apr  2 11:58:43 otto kernel: [3675742.585073] livepatch:
'lkp_Ubuntu_4_15_0_45_48_generic_49': starting patching transition
Apr  2 11:58:43 otto kernel: [3675742.740469] [p_lkrg] ALERT !!! _STEXT
MEMORY BLOCK HASH IS DIFFERENT - it is [0x918a7a1fc13e7dc9] and should
be [0xfb806a7dd458b274] !!!
Apr  2 11:58:43 otto kernel: [3675742.743774] [p_lkrg] ALERT !!! SYSTEM
HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!!
Apr  2 11:58:44 otto kernel: [3675743.259222] [p_lkrg] ALERT !!! _STEXT
MEMORY BLOCK HASH IS DIFFERENT - it is [0x918a7a1fc13e7dc9] and should
be [0xfb806a7dd458b274] !!!
Apr  2 11:58:44 otto kernel: [3675743.262512] [p_lkrg] ALERT !!! SYSTEM
HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!!
Apr  2 11:58:44 otto kernel: [3675743.834990] [p_lkrg] ALERT !!! _STEXT
MEMORY BLOCK HASH IS DIFFERENT - it is [0x918a7a1fc13e7dc9] and should
be [0xfb806a7dd458b274] !!!
Apr  2 11:58:44 otto kernel: [3675743.837264] [p_lkrg] ALERT !!! SYSTEM
HAS BEEN COMPROMISED - DETECTED DIFFERENT 1 CHECKSUMS !!!
Apr  2 11:58:45 otto kernel: [3675744.201058] livepatch:
'lkp_Ubuntu_4_15_0_45_48_generic_49': patching complete


-- 
Paweł Krawczyk
+44 7879 180015


Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.