From owner-svn-src-all@freebsd.org Tue Aug 2 00:08:31 2016 Return-Path: Delivered-To: svn-src-all@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 0DE48BA2097; Tue, 2 Aug 2016 00:08:31 +0000 (UTC) (envelope-from cse.cem@gmail.com) Received: from mail-io0-f171.google.com (mail-io0-f171.google.com [209.85.223.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id D52211BF1; Tue, 2 Aug 2016 00:08:30 +0000 (UTC) (envelope-from cse.cem@gmail.com) Received: by mail-io0-f171.google.com with SMTP id q83so198626497iod.1; Mon, 01 Aug 2016 17:08:30 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:reply-to:in-reply-to:references :from:date:message-id:subject:to:cc; bh=f+U+3TXmJ/4ae+m9EnE3Iqr7/5/LTfCKd4HELEQ5cDA=; b=YBRhuiAZpmE0Xr28IShpvG1RLXTJavYjia8fm32HrpY4UDjdClIx0BlCBfMxKh9zTx IeShW9vubCxkyJpnA84GRs60Dnk4tXgqCpxBi07qGJTsFJaulPe7DlwAW1+H+IBut0dK cO8J9gCmA4ALjEgUEPzD2sJdjMPwTDvHCrHQI5a1HwdniqLSmFyvYP4w8aRNRio36Kl6 TCIWtZ7GouVAyr0TNSvqBXKKKmy6wQYvOF9b8LiZOwEqmIa0+NyGLAFJ+lR5+hfp2iku 9i4m6UnyM2cL9sLglow6oprNjtcEmal+UkRfJqLcWj8mA7sHZ3D2AKeE5jNjhJGEKmwm p2Tw== X-Gm-Message-State: AEkoouuRJQKdC/dYFMPGfQrYP5PB4ysYhraFpicA1fu/0I2GYgzWd0a4emtsrPaxzzKi5Q== X-Received: by 10.107.3.221 with SMTP id e90mr60665061ioi.17.1470094862920; Mon, 01 Aug 2016 16:41:02 -0700 (PDT) Received: from mail-io0-f174.google.com (mail-io0-f174.google.com. [209.85.223.174]) by smtp.gmail.com with ESMTPSA id 65sm85762itl.16.2016.08.01.16.41.02 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 01 Aug 2016 16:41:02 -0700 (PDT) Received: by mail-io0-f174.google.com with SMTP id 38so197785492iol.0; Mon, 01 Aug 2016 16:41:02 -0700 (PDT) X-Received: by 10.107.147.138 with SMTP id v132mr59585356iod.27.1470094862464; Mon, 01 Aug 2016 16:41:02 -0700 (PDT) MIME-Version: 1.0 Reply-To: cem@freebsd.org Received: by 10.36.233.67 with HTTP; Mon, 1 Aug 2016 16:41:02 -0700 (PDT) In-Reply-To: References: <201608012257.u71Mv3YA030076@repo.freebsd.org> From: Conrad Meyer Date: Mon, 1 Aug 2016 16:41:02 -0700 X-Gmail-Original-Message-ID: Message-ID: Subject: Re: svn commit: r303650 - head/sys/opencrypto To: Shawn Webb Cc: src-committers , svn-src-all@freebsd.org, svn-src-head@freebsd.org, "secteam@FreeBSD.org" Content-Type: text/plain; charset=UTF-8 X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.22 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 02 Aug 2016 00:08:31 -0000 Hey Shawn, I don't think this is security-related despite being a bug in crypto-adjacent code. At best it's a DoS, I think. Cheers, Conrad On Mon, Aug 1, 2016 at 4:15 PM, Shawn Webb wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA512 > > > > On August 1, 2016 6:57:03 PM EDT, "Conrad E. Meyer" wrote: >>Author: cem >>Date: Mon Aug 1 22:57:03 2016 >>New Revision: 303650 >>URL: https://svnweb.freebsd.org/changeset/base/303650 >> >>Log: >> opencrypto AES-ICM: Fix heap corruption typo >> >>This error looks like it was a simple copy-paste typo in the original >>commit >> for this code (r275732). >> >> PR: 204009 >> Reported by: Chang-Hsien Tsai >> Sponsored by: EMC / Isilon Storage > > Since cem@ refuses to MFC even security fixes, can someone with a commit bit please MFC this within normal security-related MFC timeframe? Additionally, does a security advisory need to be sent out? CC'ing secteam@. > > Thanks, > > Shawn > > - -- > Sent from my Android device with K-9 Mail. Please excuse my brevity. > -----BEGIN PGP SIGNATURE----- > Version: APG v1.1.1 > > iQI/BAEBCgApBQJXn9ggIhxTaGF3biBXZWJiIDxzaGF3bkBzaGF3bndlYmIuaW5m > bz4ACgkQaoRlj1JFbu4Ypg//XLLOHX3y5ULHSEqEQ6tgUjQiR+9ADYKX1Zza3ghI > FsHEr7O8yi31jb8EJ9+oOiZOHxjAfLP+ezwNoa9xRUQu0IoTcCLU6PzCzHv2viaa > UZ+ae5xbB48i89o2ZshGTKgtwAzkCOhNkvPaAmS2yu14Xg+2CbhY2mCR+qdnAnMS > cUU4dTsqTI+cHQoE2ehzDst/ABSaBZa2XZKxFp3EeTb3r2bNAvh72zMv6ethU8Ht > 5VE7ZyRfQBpObZVcmSy6Sg8+vyjTRE4pdiajSqs3kIitPvxljwukMQ6DcdHCnJPx > IlOTXnM1wd7iHSwNTP8jniemOR4QrrQ3fEwglsnjp2t45ZnWi46LhfoekOinX42v > x7f+XWhcw0/oCF34q0rQ/YxFr0OcammmPMqjYKy7dlk2H6FSk9jnqh19lXu+qZP6 > UzlUS+IHHn7o0OaV9Tflsey7/24hFjEVAHFKZxsG7VzKaSjri6aJ8p2Mr2D1o1os > rEMF15pV2d9l7tIFN0FigqmffZswpTbk+uNNHc8rg+Tq7QV1fhceTgLLXRfqlpq8 > ES/Y3Epr22KCCEhftQw3fqC1XpOpn5CUc3svJx7llXWYc/c7RdxGDNSujFF3IARk > 741mx0N/ZkrcXZ/u/zk5+gMmS7NxhQXNk3QueRTIlqZv7e9GdlaYAPMZxQZKQKm3 > +YQ= > =B3c1 > -----END PGP SIGNATURE----- > >