Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 1 Aug 2016 19:58:52 -0400
From:      Shawn Webb <shawn.webb@hardenedbsd.org>
To:        Conrad Meyer <cem@freebsd.org>
Cc:        src-committers <src-committers@freebsd.org>, svn-src-all@freebsd.org, svn-src-head@freebsd.org, "secteam@FreeBSD.org" <secteam@freebsd.org>, ecturt@gmail.com
Subject:   Re: svn commit: r303650 - head/sys/opencrypto
Message-ID:  <20160801235852.GH7956@mutt-hardenedbsd>
In-Reply-To: <CAG6CVpVJffrcArygppQb0VJ=a%2Bw1coxCwZ1W62cMpgBUMDLvJQ@mail.gmail.com>
References:  <201608012257.u71Mv3YA030076@repo.freebsd.org> <EA6F519C-48ED-4335-B543-191A7758D58A@hardenedbsd.org> <CAG6CVpVJffrcArygppQb0VJ=a%2Bw1coxCwZ1W62cMpgBUMDLvJQ@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--nOM8ykUjac0mNN89
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Adding CTurt to see if he wants to take a stab at writing a PoC exploit.
It'd be cool for an offensive researcher to determine if it's simply a
DoS. But regardless, a security fix is a security fix. All
currently-supported branches really should be updated.

Thanks,

Shawn

On Mon, Aug 01, 2016 at 04:41:02PM -0700, Conrad Meyer wrote:
> Hey Shawn,
>=20
> I don't think this is security-related despite being a bug in
> crypto-adjacent code.  At best it's a DoS, I think.
>=20
> Cheers,
> Conrad
>=20
> On Mon, Aug 1, 2016 at 4:15 PM, Shawn Webb <shawn.webb@hardenedbsd.org> w=
rote:
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA512
> >
> >
> >
> > On August 1, 2016 6:57:03 PM EDT, "Conrad E. Meyer" <cem@FreeBSD.org> w=
rote:
> >>Author: cem
> >>Date: Mon Aug  1 22:57:03 2016
> >>New Revision: 303650
> >>URL: https://svnweb.freebsd.org/changeset/base/303650
> >>
> >>Log:
> >>  opencrypto AES-ICM: Fix heap corruption typo
> >>
> >>This error looks like it was a simple copy-paste typo in the original
> >>commit
> >>  for this code (r275732).
> >>
> >>  PR:          204009
> >>  Reported by: Chang-Hsien Tsai <luke.tw AT gmail.com>
> >>  Sponsored by:        EMC / Isilon Storage
> >
> > Since cem@ refuses to MFC even security fixes, can someone with a commi=
t bit please MFC this within normal security-related MFC timeframe? Additio=
nally, does a security advisory need to be sent out? CC'ing secteam@.
> >
> > Thanks,
> >
> > Shawn
> >
> > - --
> > Sent from my Android device with K-9 Mail. Please excuse my brevity.
> > -----BEGIN PGP SIGNATURE-----
> > Version: APG v1.1.1
> >
> > iQI/BAEBCgApBQJXn9ggIhxTaGF3biBXZWJiIDxzaGF3bkBzaGF3bndlYmIuaW5m
> > bz4ACgkQaoRlj1JFbu4Ypg//XLLOHX3y5ULHSEqEQ6tgUjQiR+9ADYKX1Zza3ghI
> > FsHEr7O8yi31jb8EJ9+oOiZOHxjAfLP+ezwNoa9xRUQu0IoTcCLU6PzCzHv2viaa
> > UZ+ae5xbB48i89o2ZshGTKgtwAzkCOhNkvPaAmS2yu14Xg+2CbhY2mCR+qdnAnMS
> > cUU4dTsqTI+cHQoE2ehzDst/ABSaBZa2XZKxFp3EeTb3r2bNAvh72zMv6ethU8Ht
> > 5VE7ZyRfQBpObZVcmSy6Sg8+vyjTRE4pdiajSqs3kIitPvxljwukMQ6DcdHCnJPx
> > IlOTXnM1wd7iHSwNTP8jniemOR4QrrQ3fEwglsnjp2t45ZnWi46LhfoekOinX42v
> > x7f+XWhcw0/oCF34q0rQ/YxFr0OcammmPMqjYKy7dlk2H6FSk9jnqh19lXu+qZP6
> > UzlUS+IHHn7o0OaV9Tflsey7/24hFjEVAHFKZxsG7VzKaSjri6aJ8p2Mr2D1o1os
> > rEMF15pV2d9l7tIFN0FigqmffZswpTbk+uNNHc8rg+Tq7QV1fhceTgLLXRfqlpq8
> > ES/Y3Epr22KCCEhftQw3fqC1XpOpn5CUc3svJx7llXWYc/c7RdxGDNSujFF3IARk
> > 741mx0N/ZkrcXZ/u/zk5+gMmS7NxhQXNk3QueRTIlqZv7e9GdlaYAPMZxQZKQKm3
> > +YQ=3D
> > =3DB3c1
> > -----END PGP SIGNATURE-----
> >
> >

--=20
Shawn Webb
Cofounder and Security Engineer
HardenedBSD

GPG Key ID:          0x6A84658F52456EEE
GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89  3D9E 6A84 658F 5245 6EEE

--nOM8ykUjac0mNN89
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJXn+I6AAoJEGqEZY9SRW7ukCQP/RWGGLZUhfOG6/nMofrpKl08
iTCIlc5pwlhHD85qSampF5PN0P2Hj7iztvo8h//YVBB/SE7SvG0UQ0K28pEAwhzo
9NK9EN0r86GxU/BAfzv1enHuWQP8bWrb5dCkBRMIHmOfHQ31971osD5QdX7EgqWs
8v+CaSzWM3d/RAEqG1jm6rnn3QjJsjx93U3bWj8l368p3dG6EfDRBoG9PjOHZ9bf
YnhtoIWjRS+lpVnpIckhX/zxgtdAli/05dnjkg6XXVOu8AM/bH/xVrfbNBsdrux8
QNI0YS0oIUuEjecNj+X6FQ7dY9r31E9Q1uKmz/iGZvbIZzel5OohJkcIDkBD5S4i
2dVzH4t0W26NgY0ieoxTm8mE5rIDqJZCjBq7QHxUSK1/Ii4DM4A6nLfvckzYBwOw
l1FYbW20N0meDDdzE6qzAq0qLsjzvrorxIT//nYbPmkWGWYSzr1bcFQ/ULjOhk/I
t2LAdi4pKxMBxQZN45BbVPeM+UbbsRXaNj7hfWq5IaalxXd+xfDbG33VQ/Brj7cr
jHm6frWPK8hh0ljKXrnMLAOc0I8NVL/+a8vsMpZhp+Hg6k06dHvkgF5kFBe/18gn
MZVl4Q9rkhRXUBJi+zqt99SnJa6fjcVhaAqiG1zY8OPGQguJd8CP3d4gFaG9DKOu
xGs+QFiaGxYtTorBHAMu
=XoIo
-----END PGP SIGNATURE-----

--nOM8ykUjac0mNN89--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20160801235852.GH7956>