From nobody Fri Apr 19 15:11:51 2024 X-Original-To: freebsd-security@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4VLdR02Kf4z5HD4H for ; Fri, 19 Apr 2024 15:11:56 +0000 (UTC) (envelope-from stephen.wall@redcom.com) Received: from SA9PR09CU002.outbound.protection.outlook.com (mail-southcentralusazlp170120001.outbound.protection.outlook.com [IPv6:2a01:111:f403:c10d::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client CN "mail.protection.outlook.com", Issuer "DigiCert Cloud Services CA-1" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4VLdQz3yrSz4PJs for ; Fri, 19 Apr 2024 15:11:55 +0000 (UTC) (envelope-from stephen.wall@redcom.com) Authentication-Results: mx1.freebsd.org; dkim=pass header.d=redcomlaboratories.onmicrosoft.com header.s=selector1-redcomlaboratories-onmicrosoft-com header.b="jsooLCs/"; dmarc=none; spf=pass (mx1.freebsd.org: domain of stephen.wall@redcom.com designates 2a01:111:f403:c10d::1 as permitted sender) smtp.mailfrom=stephen.wall@redcom.com; arc=pass ("microsoft.com:s=arcselector9901:i=1") ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=RKmQrzdkoFNdMLpq018NOjPf3mmV+qWHSG5NJMAavflkKLss3H/qJUXDIrKADG9os0CZz27wLMEVipXccDbB/RTBN3A4PI48RvAVR/5eWVp6cqcSUrby/AUED21AJRSwqt0ye//jwatZWD5davrb+2kSn+ByYKi7DM3U+88HjwEQfPeGl2PY0Umue0Vo+E6Q/2qrv+QMQ9XfzrjRYpUv2XGKIyY52ZfNqZubdfexSlXeQnRisEWiI2vxw4hy6dCWuhu9bsQh9EY8QNwOC3otRvZU3P/Dx877h7RO1w28BL2E/JZJ6HYwEuz4I1/2hLRNX09v/encS/NYTM2Vs49ZwQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=SclUkZJC5rAuTbmLt8f2vub6fw4OuK62AgHI5OD31Cg=; b=dngIhVSTZ5q6TWisYvuLqfba5Xu3Oy9Z26yMhfMKncA2h5e7PcvRXDDhnZWK+vJGZWL5Gn9sN/05YNSi9xOYzhZUHjN5mvgY8DW9VIaziBHNAP5jyHHEX2D4tyykyaWGEB4YkXl8WSf7yF6pRcR501/Iv9qAxhFfAr1k3qNUFsR9OR1dRYwd08SDsX1FbzU6jB0hSV+dlx5q6ktSlCsZONo+guCUbur3ckpe0H0OSJdS44U/CQEA95LoaFSMaAdEmE5RadLcI7xuWssBoKNf+1p+3f7C7gN5t4Iz//SAx//j5EEGvA7QTqc1mumfo6giuAurbBIXgyECuCfdJrDhNg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=redcom.com; dmarc=pass action=none header.from=redcom.com; dkim=pass header.d=redcom.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redcomlaboratories.onmicrosoft.com; s=selector1-redcomlaboratories-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=SclUkZJC5rAuTbmLt8f2vub6fw4OuK62AgHI5OD31Cg=; b=jsooLCs/T5IVySUYser0UcPBYFHp7E2TxQrWjeN6NPwMWJFTRPFmCpBI4alTYldDdpIMm+cQiQXI2/7TU2rLABkRgAjHZxjmpzQoIdVJIsesYCdkrTZ+pQv4XWLqR7MRRbAQyAHIazNxzZkPx5Um2ndCnK8PHrZMnmfH5KjsT2ZTArrWRsU5vYr3JAg9u0F2wi/XXeDkn7h0P6OZZHXh9K3ov5CjJfVYiL2MVkDNwSdKPbyeMXO4I6wQyV8YKIojUr4XEV/ZriYETEYQXrx8Xo6AusuW67OHOFex8N9wleCSLWCBrqBqXKtM4PC6nTbevnNAowUTIElWij7byxgKig== Received: from MW4PR09MB9284.namprd09.prod.outlook.com (2603:10b6:303:1f2::12) by SJ0PR09MB6030.namprd09.prod.outlook.com (2603:10b6:a03:26d::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7472.44; Fri, 19 Apr 2024 15:11:51 +0000 Received: from MW4PR09MB9284.namprd09.prod.outlook.com ([fe80::7849:d1ba:7ac7:46e]) by MW4PR09MB9284.namprd09.prod.outlook.com ([fe80::7849:d1ba:7ac7:46e%4]) with mapi id 15.20.7472.037; Fri, 19 Apr 2024 15:11:51 +0000 From: "Wall, Stephen" To: "freebsd-security@freebsd.org" Subject: RE: FreeBSD Security Advisory FreeBSD-SA-24:03.unbound Thread-Topic: FreeBSD Security Advisory FreeBSD-SA-24:03.unbound Thread-Index: AQHagOWRjQu9lqMWJE2hGRCC6LnFwrFv0gWw Date: Fri, 19 Apr 2024 15:11:51 +0000 Message-ID: References: <20240328075102.10441343C@freefall.freebsd.org> In-Reply-To: <20240328075102.10441343C@freefall.freebsd.org> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-publictraffictype: Email x-ms-traffictypediagnostic: MW4PR09MB9284:EE_|SJ0PR09MB6030:EE_ x-ms-office365-filtering-correlation-id: 8136667c-5b2e-4fb1-f9d2-08dc60830a7b x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0; x-microsoft-antispam-message-info: theee35OdgSOhzCGCIm8Zgw0a8mBxCbTUFQbjsPVaUZsO6O3OVqa7NLnbB3oshdCEBSkm5J2YGXour8J2t1whFnG+VDHokbhcVcQ/nH6S1eVuNnfgNyBz3wNvi2bsPXFDe/r2miicOSzP/da97/fS/kNMD9RhLbDwVsCQ4l/dbvLREhCzlH08QyeWSOGa1yAROgXoWQMp03J8Rl1QWvKbEAQ5O8rpVS9jD4Ct0dFlJm262MIN7YxytpyI3AlORRtMgmH4xgxcqRsgwEHJDvMgYuGndOVhCuR3n8hAzySGP4fP/OviHsDCTwAxTVq0OaS9u8tLI7twyBGsCHKhB0yQAxHy9qsOuFyV8qdaZXMN81QeIkL3Ziak+UXKcVJEFMKwrHfdOyW8o8tzuF77DO2hL+0Xtuzob1ii4FKxa+/18GU06xoZ+pjXACPwvkdQNFUk9H/D/DmRj9iu22zdcf1si1IYmkNtUyy83C6xhXnEeusMSJiyclvvms9zRIvlyeOaP38mdvNSAKAwghxrNd50XbYswR2EIUsVCilAsrHhuW8IAlEVAzKMfr38cFFwpqMROKD2Y5mECL/SiHH99zcKnseGBJSS84FQZ5aPL/hH0jVmGD5U+p7/ZtoHIr4LJHff3esI0WiwY29Q8QrL/03SEmnMhd1CB8b9hzb0pMmv0oC/bR3W7uNDbFjcRSEvuwVBFju4btdOoh4G7/skrYpFHpbKb2iuZKIWgChL76jZNw= x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MW4PR09MB9284.namprd09.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230031)(41320700004)(366007)(1800799015)(38070700009);DIR:OUT;SFP:1102; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?utf-8?B?akY3NHltVk80TWZnSys4dXB0YkZIeWRFT1FrVnVkUVh6VmN5emw0cHdUR2JU?= =?utf-8?B?dlRxTDdCbXMxRTc0cC9NbHVOY3lCY2c3Rk1za2F1R3czUXpwR3AxcC95eHBN?= =?utf-8?B?elNkdER3TEd6aCs1MzhSNnR0YVpNemw4N3M4MXQ2UktrclVzeWhNRDhpQmZq?= =?utf-8?B?ZXZpS0FIL0RZRDJNNHJsczdGeUFiUzhwK1M4OS9HWDdIWSs3QjZua2ZuN1Yy?= =?utf-8?B?eTZOS2JFeUxyTk54UEFtSFVydzd5bjZZRnRoaHgzZGduaVh4OVFnMVVtd014?= =?utf-8?B?NGNrcGFieGJpcXNKdGVrdUY2YkdPM3o5ZTZXUU1qNS9QRmNXU2FnYXk5VnFJ?= =?utf-8?B?NEtzRG93amExclJMTTJEOHA4OUZsSVZ4bWttOEdEYy9xK2RlcS9VcXRucnVi?= =?utf-8?B?ZVYvRS9QYUhVd2FteTA1UWgxYUlOYWlndVFOZmZzTnBTcjdpbEdoTms5M0Z4?= =?utf-8?B?VWhyd1NaN05VbDlYVVBham9hNGR1L3VGd3dMczJaeXRrc2k2cmRDb21QZ2NT?= =?utf-8?B?eVd3bDhORmRJVWtRSFM4UWhGMW5jaWNrVFp6S0ZqMHozdDg3ZnVRUUQwRUdo?= =?utf-8?B?V1cvVllKdGJjZ1RxbTRRbVd1Rkl4QkV4dk5ZQXBYYWtVdC9ib2VyUWtNZDdw?= =?utf-8?B?SFRWaFpFdGgxMUkvd2Q1bm9wZlV5eEl3NjZ0aHM2bk5ndEkwT3BOT1B0NXkr?= =?utf-8?B?d1puWForQ2xiSnkrRkhQVDhWdEYwc1hmQm11dTNhTXNGRTR5eVpMNFFZSVBT?= =?utf-8?B?cE5DWTN0aUozbThzVzhZZ21kWUQ0d1d4UWZHLzQrT0hrb3lQOEJZT290cDc5?= =?utf-8?B?amtpS0E2QlBHTm9Lbms4VlhhUlFFSTJaSWt0ZGZqcVZvSW9PRVpnSWMydlQz?= =?utf-8?B?WEx2em0zbFFzQUFqM0V5NjNxQWg4SjN0VW9iYjF3UEpvYlFZKzVuM0RWNmZP?= =?utf-8?B?aFA4QTJGclREWkJ2V05nN2xub1R6cHl4NTlsbjRaNmNhdHZQQmVlZTVSWGlB?= =?utf-8?B?KzlPa0ZzL1Q4MXZYQ3ArUTRBcWZwVTZOVEV3TnRCc3lrcFl2M0FqUmR3Y21j?= =?utf-8?B?SmFVbGlhT1B4ZHhvbFJvOWlZL09xanRQQ3Z4QzV0V1RGNVNwKzh4UXpoRkFC?= =?utf-8?B?d3A1WW9MVWp5MTlLZlFQNFlrWnlpTHNiaGJXQXB3UHVkNm9FWE5sb2JRSnNU?= =?utf-8?B?Qm9ZQTZoRWRmcHl6ME40c1NsV0xhK3gvdjNSdGw5UlVpSUNncE5BV25saXNK?= =?utf-8?B?RTZZQzk2RUxOcnY0b1dxM3BGTHhnclFPNWd2eXFnSklWTHFMZW5mWXpnTXJJ?= =?utf-8?B?TzA4cUlodWVNaGM2ekhDR0lMZTZsRnlndTZCZzBRM0YwWnoxR1RCMnd2THFk?= =?utf-8?B?Y1I1ZmVNRTBmUlJiblJFTzcvTjR2MGlpRGtYYjkxNHFyK3VWaVMxb0dLZCtI?= =?utf-8?B?VlBlWkVaT1oxSzNzU2U3Z2xjYnF2bFJSQmlpaUVYNXY1Si8rRWtGbWhrS3py?= =?utf-8?B?cjNZM1pkQmhTTVlLZGRhSG9PS3gveDZZTDhkbEdQcEk2VlB4ZENqYzRJbW1v?= =?utf-8?B?ZTlMUk92SS9YMGRBTzNPeGRLUUFWLzBEUEo5cFIzWkE4aVIrcTVlWnFiQURq?= =?utf-8?B?TXJCOXY5K3haa200ZWNMRVgrSUtpVTBtMDcxa3lBc3hrck94clQzNUNMb1N2?= =?utf-8?B?UlpkaW4zaDgrcnNyMWl3cjlkK29ja3dvTFpSV2tUWVBBQ2pmWHVuOVU4aHRP?= =?utf-8?B?TWNmN0kyeXYyVUg5QUczR3RsOHU0TkRtNHFUQ3N5elFLV3RiNjI0UnBiZExW?= =?utf-8?B?ejZlOStyRjlrcVUwZFBiOEd3ZXFvQ1l1LzlBbVpiSG1BcjQ4Mm1YSDZCOXBu?= =?utf-8?B?S0NuWTVuR3pOWlBUdlVyaG5za0IxVy9XNTZ1enk5T1c1WWhsbEM2VU5LbFpK?= =?utf-8?B?Y0syNWZCZDZFYnZTM3lQNTg1a2hQOGRvVXlaUnEway9leVpoNFBIcTZXdWRN?= =?utf-8?B?NTdPYkpNZUtzbExnUmd6Rm9zTU5tY0NNVERIV0wzMy8wTk5PQTRXSFVUZlMw?= =?utf-8?B?Wm1Nd3NYTEtLSE55cWRSMHlFMkFBTW0yT1dZMjY3bWdRbUl3NmJQR09oTnJP?= =?utf-8?Q?i/2U=3D?= Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 List-Id: Security issues List-Archive: https://lists.freebsd.org/archives/freebsd-security List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: freebsd-security@freebsd.org Sender: owner-freebsd-security@FreeBSD.org MIME-Version: 1.0 X-OriginatorOrg: redcom.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: MW4PR09MB9284.namprd09.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: 8136667c-5b2e-4fb1-f9d2-08dc60830a7b X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Apr 2024 15:11:51.2014 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 86200ba5-6348-4d6f-bdd7-96f43e8d9247 X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ0PR09MB6030 X-Spamd-Bar: --- X-Spamd-Result: default: False [-3.40 / 15.00]; ARC_ALLOW(-1.00)[microsoft.com:s=arcselector9901:i=1]; NEURAL_HAM_MEDIUM(-1.00)[-1.000]; NEURAL_HAM_LONG(-1.00)[-1.000]; MIME_BASE64_TEXT_BOGUS(1.00)[]; NEURAL_HAM_SHORT(-1.00)[-1.000]; R_SPF_ALLOW(-0.20)[+ip6:2a01:111:f403:c000::/51]; R_DKIM_ALLOW(-0.20)[redcomlaboratories.onmicrosoft.com:s=selector1-redcomlaboratories-onmicrosoft-com]; MIME_BASE64_TEXT(0.10)[]; MIME_GOOD(-0.10)[text/plain]; RCPT_COUNT_ONE(0.00)[1]; MISSING_XM_UA(0.00)[]; ASN(0.00)[asn:8075, ipnet:2a01:111:f000::/36, country:US]; MIME_TRACE(0.00)[0:+]; FROM_HAS_DN(0.00)[]; MLMMJ_DEST(0.00)[freebsd-security@freebsd.org]; RCVD_TLS_LAST(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DMARC_NA(0.00)[redcom.com]; RCVD_COUNT_TWO(0.00)[2]; TO_MATCH_ENVRCPT_ALL(0.00)[]; TO_DN_EQ_ADDR_ALL(0.00)[]; DKIM_TRACE(0.00)[redcomlaboratories.onmicrosoft.com:+] X-Rspamd-Queue-Id: 4VLdQz3yrSz4PJs PiBGcmVlQlNELVNBLTI0OjAzLnVuYm91bmQgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAg ICAgICBTZWN1cml0eSBBZHZpc29yeQ0KPiANCj4gVG9waWM6ICAgICAgICAgIE11bHRpcGxlIHZ1 bG5lcmFiaWxpdGllcyBpbiB1bmJvdW5kDQoNClNpbmNlIHVwZ3JhZGluZyB0byBwNiBpbiByZXNw b25zZSB0byB0aGlzIFNBLCB3ZSd2ZSBmb3VuZCB0aGF0IGtpbml0IGhhcyBzdGFydGVkDQpmYWls aW5nIGZvciB1cy4gVGhpcyBsb29rcyB0byBiZSBkdWUgdG8gYWFmMmM3ZmRiOCBbMV0sIHdoZW4g aXQgYXR0ZW1wdHMgdG8gbG9hZA0KdGhlIGxlZ2FjeSBPcGVuU1NMIHByb3ZpZGVyLCB3aGljaCB3 ZSBkbyBub3QgaW5zdGFsbCBvbiBvdXIgc3lzdGVtcy4NCkZ1cnRoZXJtb3JlLCBpdCBsb2FkcyB0 aGUgZGVmYXVsdCBwcm92aWRlciBhcyB3ZWxsLCB3aGljaCB3ZSBzcGVjaWZpY2FsbHkgZG8gbm90 DQpsb2FkIHdoZW4gc3lzdGVtcyBhcmUgY29uZmlndXJlZCBmb3IgRklQUyBvcGVyYXRpb24uDQoN CldoYXQgaXMgb3VyIGV4cG9zdXJlIGlmIHdlIHNpbXBsZSByZXZlcnQgdGhpcyBjb21taXQ/ICBB cmUgdGhlcmUgYW55IENWRSdzDQphc3NvY2lhdGVkIHdpdGggaXQ/ICBJcyB0aGVyZSBhIHdheSB0 byBkaXNhYmxlIHRoZSBjaXBoZXJzIGF0IGJ1aWxkIHRpbWUgdGhhdA0KY2FuIHRyaWdnZXIgdGhl IHNlZ2ZhdWx0cz8NCg0KT3IgYW0gSSBvbiBteSBvd24gcmVzb2x2aW5nIHRoaXMgYmVjYXVzZSB3 ZSBkbyBub3QgdXNlIHRoZSBsZWdhY3kgcHJvdmlkZXIgKEkuZS4NCm5vdCBhIGRlZmF1bHQgc3lz dGVtKT8NCg0KVGhhbmtzIGZvciB5b3VyIGNvbnNpZGVyYXRpb24uDQoNCi0gU3RldmUgV2FsbA0K DQpbMV0gaHR0cHM6Ly9jZ2l0LmZyZWVic2Qub3JnL3NyYy9jb21taXQvP2g9cmVsZW5nLzE0LjAm aWQ9YWFmMmM3ZmRiODFhMWRkOWRlOWZjNzdjOTMxM2Y0ZTYwZTY4ZmE3Ng0K