News: 1603670041

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Linus Torvalds hails ‘historic’ Linux 5.10 for ditching defunct addressing artefact

(2020/10/26)


Linus Torvalds has given the world the first release candidate of version 5.10 of the Linux kernel and called out what he’s labelled an historic change – the removal of an addressing tool that appears to have been around for nearly 30 years, sparked a nasty bug a decade ago but has since been made redundant by chipmakers.

That scheme is called set_fs() and allows the Linux kernel to override address spaces, which was a handy thing to do with Intel’s 286 and 386 CPUs.

As Torvalds [1]explained in his weekly kernel update, set_fs() controls “whether a userspace copy actually goes to user space or kernel space”. That matters because, as was detailed in 2010 in [2]CVE-2010-4258 , it could be used to “overwrite arbitrary kernel memory locations, and gain privileges”.

This looks to be a bigger release than I expected. I'm not entirely sure whether this is just a general upward trend or just a fluke.

The bug was fixed, again way back in 2010, and over time chip-designers have moved on to improved memory management techniques. Torvalds wrote that this sort of memory space override has been banished from the x86, powerpc, s390 and RISC-V architectures.

But set_fs() , which Torvalds says “goes back to pretty much the original release of Linux”, has persisted.

Until now.

“It's not a _huge_ change, but it's interesting,” Torvalds wrote, adding: “to most people that all shouldn't matter at all, and it's mainly a small historical footnote that 5.10 no longer relies on the whole set_fs() model.”

Torvalds rated the rest of the release “fairly normal.”

Linux 5.10 to make Year 2038 problem the Year 2486 problem [3]READ MORE

“This looks to be a bigger release than I expected, and while the merge window is smaller than the one for 5.8 was, it's not a *lot* smaller. And 5.8 was our biggest release ever,” he wrote, noting that it includes almost 14,000 commits from “closer to 1,700 people.

“I'm not entirely sure whether this is just a general upward trend (we did seem to plateau for a while there), or just a fluke, or perhaps due to 5.9 dragging out an extra week. We will see, I guess.”

Big changes in this version of the kernel include end of support for PowerPC 601 CPUs, support for Nvidia’s Orin SOCs intended for use in self-driving cars and robots, better support for the graphics driver in the Broadcom CPU used in the Raspberry Pi 4, revised Spectre mitigation for Arm CPUs and the usual bunch of accommodations for upcoming CPU and GPUs, virtualisation tweaks and crushing the year 2038 bug. ®

Get our [4]Tech Resources



[1] http://lkml.iu.edu/hypermail/linux/kernel/2010.3/00552.html

[2] https://nvd.nist.gov/vuln/detail/CVE-2010-4258

[3] https://www.theregister.com/2020/10/19/linux_5_10_y2k38_fixes/

[4] https://whitepapers.theregister.com/

Trim that long gray tail

Anonymous Coward

I'd like to see this called out more often. Seeing bits taken out as no longer needed means to me they are tracking the codebase well. Lest the ghosts of architectures past rise and trouble everyone's sleep in exploits.

Yes, but...

Yes Me

Wanna bet that no box somewhere is gonna install this and brick itself as a result? There's always one out there.

bye bye 2038

Anonymous Coward

Happy to see "crushing the 2038 bug"

Sometimes even to live is an act of courage.
-- Seneca