From owner-freebsd-security@freebsd.org Tue Jun 20 20:22:48 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id B9E1DDA15EA for ; Tue, 20 Jun 2017 20:22:48 +0000 (UTC) (envelope-from carpeddiem@gmail.com) Received: from mail-it0-x235.google.com (mail-it0-x235.google.com [IPv6:2607:f8b0:4001:c0b::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 7D9A872469 for ; Tue, 20 Jun 2017 20:22:48 +0000 (UTC) (envelope-from carpeddiem@gmail.com) Received: by mail-it0-x235.google.com with SMTP id m47so20879935iti.1 for ; Tue, 20 Jun 2017 13:22:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=XaKzLQe4XWArlqSz81EPRxP8bwuhsFBGFR8mt8ivtr0=; b=pm6GhcvGwholW1ACtZMJ32SmYUtTavQ1FrdCM7bp5YFNNZwYDkehCxcmI3I5Rw9kuJ i/blAh3Zrz15CimwBRmGC6tz0h5BtmrQQ48kYjjjyLCrAT1nV8H21OyC796hO0ylwARd auWbUFZFb+qG/tMSxE8bdWjoBpV98LG9ieBP2sPGISAkkiw4ZYh/YzZ6IV/fHsEH9ilW Vrk2qhvISgjKTK9tiFKwoVdLytOnSdrd+iIKjbWK4K/g0yvgctmujfs9mfRjpV6r5Y/G MD4ZffTcw9Mlv4DwuRqo3eM7Dh78Vrcok0kNUr3NQvchIwAmMdmGf3IQghaRFy0e0P+l ZwnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=XaKzLQe4XWArlqSz81EPRxP8bwuhsFBGFR8mt8ivtr0=; b=OZxyK75t+sAGyHX0qBRYewiLi4tJ6yC/4AshovdFiw3nlX/vM2B1IiIgINasNLzE5L 64ZjjnsFzDaE++PMRzhaB+j2YmburCWv/218PDnf2j8kOwtwcMCVLkMOcjSx0ewsChnc ATNJxcPsEq3p8g+O82Bz7YivrqLIfC5f2V7l5evUsb1kTTaC0za8rDSwqFPGkQU78vZ3 R/YuRzDBsaSZK3MyfBW/rtJ3dY5vZcY0ipF6sgutFX/BFBpY52Qbz+NZ9U16GLszdjxf vg3fynJGnnDRUB+kVynkTe/M4e+nj/dY2vOTJl6EFMRsfRZ/dWIsQHFFzv8xmXX8L4Kl qfqg== X-Gm-Message-State: AKS2vOwLtNaTB7SY2b8LOvmFkPewm5TFlSKhpOSwEByMBqOQHeXRKv5G cIj+pGvckQ7T7/sI5tsUBG8LgOXIbw== X-Received: by 10.36.65.18 with SMTP id x18mr5473760ita.88.1497990167993; Tue, 20 Jun 2017 13:22:47 -0700 (PDT) MIME-Version: 1.0 Sender: carpeddiem@gmail.com Received: by 10.107.10.86 with HTTP; Tue, 20 Jun 2017 13:22:27 -0700 (PDT) In-Reply-To: References: From: Ed Maste Date: Tue, 20 Jun 2017 16:22:27 -0400 X-Google-Sender-Auth: lcMrQ_VtfUIGzHX3dQeumvDqKuA Message-ID: Subject: Re: The Stack Clash vulnerability To: Vladimir Terziev Cc: "freebsd-security@freebsd.org" Content-Type: text/plain; charset="UTF-8" X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 20 Jun 2017 20:22:48 -0000 On 20 June 2017 at 04:13, Vladimir Terziev wrote: > Hi, > > I assume FreeBSD security team is already aware about the Stack Clash vulnerability, that is stated to affect FreeBSD amongst other Unix-like OS. Yes, the security team is aware of this. Improvements in stack handling are in progress (currently in review).