From nobody Tue Nov 19 13:19:50 2024 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Xt4q02gyzz5f1bR for ; Tue, 19 Nov 2024 13:19:56 +0000 (UTC) (envelope-from gabor@zahemszky.hu) Received: from smtp-4-out.integrity.hu (smtp-4-out.integrity.hu [212.52.165.214]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "*.integrity.hu", Issuer "RapidSSL TLS RSA CA G1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Xt4pz0CK7z4tgq for ; Tue, 19 Nov 2024 13:19:54 +0000 (UTC) (envelope-from gabor@zahemszky.hu) Authentication-Results: mx1.freebsd.org; dkim=none; spf=pass (mx1.freebsd.org: domain of gabor@zahemszky.hu designates 212.52.165.214 as permitted sender) smtp.mailfrom=gabor@zahemszky.hu; dmarc=none Received: from webmail.integrity.hu (mail-fe-2.integrity.hu [10.1.64.122]) (Authenticated sender: gabor@zahemszky.hu) by mail-smtp.integrity.hu (Postfix) with ESMTPA id 8ECA340575 for ; Tue, 19 Nov 2024 14:19:50 +0100 (CET) Received: from Ny2VJRTnD/41MWTh1K9Pcdu7KAq3qwvVsnLpIkYbYD7hZ2SohnyEMA== (4F5vC96b3M9Fc9ZqMy+1Oa0rXQMAsuIl) by webmail.integrity.hu with HTTP (HTTP/1.1 POST); Tue, 19 Nov 2024 14:19:50 +0100 List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 Date: Tue, 19 Nov 2024 14:19:50 +0100 From: =?UTF-8?Q?Zahemszky_G=C3=A1bor?= To: freebsd-security@freebsd.org Subject: Re: FreeBSD-SA-24:18.ctl impacted systems In-Reply-To: References: Message-ID: X-Sender: gabor@zahemszky.hu Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Spamd-Result: default: False [-3.27 / 15.00]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_LONG(-1.00)[-1.000]; NEURAL_HAM_SHORT(-0.97)[-0.969]; R_SPF_ALLOW(-0.20)[+ip4:212.52.165.212/30]; MIME_GOOD(-0.10)[text/plain]; RCVD_VIA_SMTP_AUTH(0.00)[]; FROM_HAS_DN(0.00)[]; RCPT_COUNT_ONE(0.00)[1]; ASN(0.00)[asn:28924, ipnet:212.52.165.0/24, country:HU]; MIME_TRACE(0.00)[0:+]; FREEFALL_USER(0.00)[gabor]; MISSING_XM_UA(0.00)[]; MID_RHS_MATCH_FROM(0.00)[]; R_DKIM_NA(0.00)[]; MLMMJ_DEST(0.00)[freebsd-security@freebsd.org]; TO_DN_NONE(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; FROM_EQ_ENVFROM(0.00)[]; ARC_NA(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; RCVD_TLS_LAST(0.00)[]; PREVIOUSLY_DELIVERED(0.00)[freebsd-security@freebsd.org]; DMARC_NA(0.00)[zahemszky.hu]; RCVD_IN_DNSWL_NONE(0.00)[212.52.165.214:from] X-Rspamd-Queue-Id: 4Xt4pz0CK7z4tgq X-Spamd-Bar: --- Hi! (Only on ctld: ) You can build an iSCSI SAN from a FreeBSD machine with ctld. Zahy 2024-11-18 15:37 időpontban Wall, Stephen ezt írta: > Good day, folks. > > I am seeking clarification of statements in > https://www.freebsd.org/security/advisories/FreeBSD-SA-24:18.ctl.asc. > > Section III, Impact says “A malicious guest could cause a Denial of > Service (DoS) on the host.” > > Does this imply that only FreeBSD systems acting as a Virtualization > Manager are impacted? Or could other VM hosts be impacted by a > FreeBSD guest? And are bare metal installations affected at all? > > Also, I am unfamiliar with ctld(8) – is it only used with > virtualization, or could it be used in the aforementioned bare metal > FreeBSD, and for what purpose? > > Thank you. > > Steve Wall > > -- > > Stephen Wall > > Senior Staff Software Engineer > > 585.924.7550 > > REDCOM Laboratories, Inc. [1] > > Research, Engineering, & Development in Communications > > One Redcom Center, Victor, NY 14564-0995 > > > > Links: > ------ > [1] https://www.redcom.com/