From owner-freebsd-questions@freebsd.org Wed Jul 3 09:05:34 2019 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 54D7A15CCF4E; Wed, 3 Jul 2019 09:05:34 +0000 (UTC) (envelope-from grarpamp@gmail.com) Received: from mail-io1-xd43.google.com (mail-io1-xd43.google.com [IPv6:2607:f8b0:4864:20::d43]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) server-signature RSA-PSS (4096 bits) client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "GTS CA 1O1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 6981869E98; Wed, 3 Jul 2019 09:05:33 +0000 (UTC) (envelope-from grarpamp@gmail.com) Received: by mail-io1-xd43.google.com with SMTP id u13so3073500iop.0; Wed, 03 Jul 2019 02:05:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=oYV9irRwxmKAIylx4EvJWUJjALFORwe/s/SPbFyKwCk=; b=J1+qSzdFBFp7NOdXv84lUu6gVTVjYT1Q04WWQ6QdEgHO0/osX8LZykygFerVzKnKvq wmC+Rz2QJhgp6tqto1MJsk9o2qYsENTVEaNBJ9sRGvq3+ziQYz9Olz4tCWr4+rLrF3Ax BemcmJL6Ks4UHRoVA35Ej9/XvlbIAUPG6CH3+8PsZpqzXyEfnE0EZYt8o+ev2+bassZy 2y7RSToO7O4v6TmCBClgCCBpffXlvXYz6qwTvngIGcqwK1eMzu7Mi2GpdTdc3uhTzcNp 9eS9LX1IU5K320NryAeJ8tvUT0QywdbIadrnLC4iKZJzpI6Vnu85lmF5gjockBlDppsN w+ng== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=oYV9irRwxmKAIylx4EvJWUJjALFORwe/s/SPbFyKwCk=; b=T/IkDyVb9xPx6iWhLRNtojehsgrMOakUVvPTz0kFkIbOVD0aHYRCHLy/X160ZwX9zy 18pogLwiiD350uGMjeBFN2JLYFWPPJ0An2uDQI87EAPnRHV2F1u+SB4QtNWl0nU89/af QsY5NVSKt76HtqrMoyr1w1Y2yNj23l1YdMQugY5I9hrb2yVWeI9ULe4Xi3leiiWeqFPU ck7vGnqO5gsKAVgO/NG4+iGj7GWxBgxN8VEeXtieBdnrSEwUud22mjqQft6bh8KEEFEx U8naijXLBnBPmt11s/5VongoWc1zr433gyBrUVeOenO7xdNMm6In2/iB9x4YXDhfUXZm mXqw== X-Gm-Message-State: APjAAAUsr2fWE8EMpmb3iP6X9ZTTKy3tYHrtOxmLhqfn9HDBcNiOn93C PZu1E8Vd1t1xre19t7K0XGRaPLQ/DggM9f+jO0vcmbxi X-Google-Smtp-Source: APXvYqy2y7gSYoZ4cFbdpQ28vA/4w/T3uIggJujGxNH7tN7Hjn4H4m7Em+6F8JQCmuRY1KtXOSyujaRPGPv0MRJFkvo= X-Received: by 2002:a5d:9d58:: with SMTP id k24mr12033625iok.116.1562144732490; Wed, 03 Jul 2019 02:05:32 -0700 (PDT) MIME-Version: 1.0 Received: by 2002:a02:81c6:0:0:0:0:0 with HTTP; Wed, 3 Jul 2019 02:05:31 -0700 (PDT) In-Reply-To: References: <20190618235535.GY32970@gmail.com> From: grarpamp Date: Wed, 3 Jul 2019 05:05:31 -0400 Message-ID: Subject: Re: CVE-2019-5599 SACK Slowness (FreeBSD 12 using the RACK TCP Stack) To: freebsd-security@freebsd.org Cc: freebsd-questions@freebsd.org, jtl@freebsd.org, freebsd-core@freebsd.org, info@freebsdfoundation.org Content-Type: text/plain; charset="UTF-8" X-Rspamd-Queue-Id: 6981869E98 X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=gmail.com header.s=20161025 header.b=J1+qSzdF; dmarc=pass (policy=none) header.from=gmail.com; spf=pass (mx1.freebsd.org: domain of grarpamp@gmail.com designates 2607:f8b0:4864:20::d43 as permitted sender) smtp.mailfrom=grarpamp@gmail.com X-Spamd-Result: default: False [-4.57 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-0.998,0]; R_DKIM_ALLOW(-0.20)[gmail.com:s=20161025]; FROM_HAS_DN(0.00)[]; R_SPF_ALLOW(-0.20)[+ip6:2607:f8b0:4000::/36]; FREEMAIL_FROM(0.00)[gmail.com]; MIME_GOOD(-0.10)[text/plain]; TO_DN_NONE(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; RCPT_COUNT_FIVE(0.00)[5]; RCVD_COUNT_THREE(0.00)[3]; TO_MATCH_ENVRCPT_SOME(0.00)[]; DKIM_TRACE(0.00)[gmail.com:+]; MX_GOOD(-0.01)[cached: alt3.gmail-smtp-in.l.google.com]; DMARC_POLICY_ALLOW(-0.50)[gmail.com,none]; RCVD_IN_DNSWL_NONE(0.00)[3.4.d.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.4.6.8.4.0.b.8.f.7.0.6.2.list.dnswl.org : 127.0.5.0]; IP_SCORE(-0.79)[ip: (1.60), ipnet: 2607:f8b0::/32(-3.15), asn: 15169(-2.36), country: US(-0.06)]; NEURAL_HAM_SHORT(-0.77)[-0.771,0]; FROM_EQ_ENVFROM(0.00)[]; MIME_TRACE(0.00)[0:+]; FREEMAIL_ENVFROM(0.00)[gmail.com]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; RCVD_TLS_LAST(0.00)[]; DWL_DNSWL_NONE(0.00)[gmail.com.dwl.dnswl.org : 127.0.5.0] X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 03 Jul 2019 09:05:34 -0000 On 6/24/19, grarpamp wrote: > On 6/18/19, grarpamp wrote: >> https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md >> As it is not in the current .md, when was the issue >> discovered by Netflix / Looney? > > One week has gone by, so asking again... This is now into *third* week and *third* time this very simple questions has been asked pursuant "actual discussion around disclosure policies", from two public and at least one private party, with zero response. Optics fogging up. Escalating as such. Thanks. > When was the issue discovered by Netflix / Looney? > When did FreeBSD become aware of the issue?