[Bug 1820798] Re: hardening-check: add support for detecting stack clash protected binaries
Alex Murray
alex.murray at canonical.com
Sun Mar 31 23:14:53 UTC 2019
Will let the foundations team decide on the importance of this but the
security team is keen for this to land in 19.10 / EE to support the
toolchain hardening updates so I hope this is seen as a higher priority
than Wishlist.
** Changed in: devscripts (Ubuntu)
Importance: Wishlist => Undecided
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to devscripts in Ubuntu.
https://bugs.launchpad.net/bugs/1820798
Title:
hardening-check: add support for detecting stack clash protected
binaries
Status in devscripts package in Ubuntu:
New
Bug description:
The security team is in the process of making -fstack-clash-protection
enabled by default in gcc-8/9 for 19.10 / 20.04. To support this it is
useful to be able to detect binaries which include this new feature
via hardening-check. Unlike previous features this can only be
detected by looking for the sequence of instructions which perform
this feature in the disassembly output via objdump.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/devscripts/+bug/1820798/+subscriptions
More information about the foundations-bugs
mailing list