Starting to think that the @grsecurity kernel is not suitable for prod. First SIZE_OVERFLOW false +s, now panic due to a bug they introduced
-
-
Replying to @marcan42
@marcan42@grsecurity SIZE_OVERFLOW has false positives by design due to GCC limitations. Shouldn't enable if DoS is more important to you.1 reply 0 retweets 0 likes -
Replying to @CopperheadOS
@marcan42@grsecurity And in addition to that, it catches both intended and benign unintended overflows. So it can be painful to use it.1 reply 0 retweets 0 likes -
Replying to @CopperheadOS
@CopperheadSec@grsecurity Yes, I stopped turning it on on prod servers. But the irony here is it caught a *real* bug *introduced* by grsec.1 reply 0 retweets 1 like
@CopperheadSec @grsecurity Heck, for all I know the bug may even be exploitable without SIZE_OVERFLOW...
5:30 PM - 25 Apr 2016
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.