login
Login
/
Register
Search
Search this site:
Forums
News
Blogs
Features
Site
Home
»
Mailing list archives
»
linux-kernel
»
2007
»
September
»
28
Re: PATCH: tcp rfc 2385 security/bugfix for sparc64
view
thread
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
[view in full thread]
From: David Miller
Subject:
Re: PATCH: tcp rfc 2385 security/bugfix for sparc64
Date: Friday, September 28, 2007 - 2:20 pm
From: "Peter Lieven" <pl@dlh.net> Date: Fri, 28 Sep 2007 22:42:25 +0200 (CEST)
quoted text
> TCP MD5 signatures on sparc64 (big-endian) completely fail on current > kernel releases in interoperability with Cisco/Foundry or other > little-endian linux systems. > > The root cause is a cast in the return statement of tcp_v4_md5_do_lookup, > where a tcp4_md5sig_key is casted onto tcp_md5sig_key without proper > conversion. On little-endian systems the upper 8 bits are cut of which > yields the expected behaviour. However, on big-endian systems (like > sparc64) only the most significant 8 bits are preserved. Since > TCP_MD5SIG_MAXKEYLEN is 80, this always yields 0. > > In the calculation of the md5 signature afterwards the key is therefore > not appended to the tcp segment which could result in a security problem > since only the presence of a md5 signature is checked, and the key itself > doesn't matter.
Thanks for finding this bug.
quoted text
> --- linux.old/include/net/tcp.h 2007-09-28 21:43:26.000000000 +0200 +++ > linux/include/net/tcp.h 2007-09-28 21:45:35.000000000 +0200 @@ -1055,6 > +1055,7 @@ static inline void clear_all_retrans_hin
I'll have to apply this patch by hand because your email client completely corrupted the patch.
quoted text
> Signed-off-by: Peter Lieven <pl@dlh.net> > Signed-off-by: Matthias M. Dellweg <2500@gmx.de>
Thanks again. -
unsubscribe notice
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to
majordomo@vger.kernel.org
More majordomo info at
http://vger.kernel.org/majordomo-info.html
Please read the FAQ at
http://www.tux.org/lkml/
Previous message: [
thread
] [
date
] [
author
]
Next message: [
thread
] [
date
] [
author
]
Messages in current thread:
PATCH: tcp rfc 2385 security/bugfix for sparc64
, Peter Lieven
, (Fri Sep 28, 1:42 pm)
Re: PATCH: tcp rfc 2385 security/bugfix for sparc64
, David Miller
, (Fri Sep 28, 2:20 pm)
Re: PATCH: tcp rfc 2385 security/bugfix for sparc64
, David Miller
, (Fri Sep 28, 2:30 pm)
Navigation
Mailing list archives
Recent posts
Popular discussions
linux-kernel
:
Ingo Molnar
Re: [PATCH 0/3] v2 Make hierarchical RCU less IPI-happy and add more tracing
Jeremy Fitzhardinge
Re: Linux 2.6.28.10 and Linux 2.6.29.6 XEN Guest Support Broken x86_64 in BUILD
Nick Piggin
Re: [patch] CFS (Completely Fair Scheduler), v2
Gary Hade
Re: [PATCH 0/5][RFC] Physical PCI slot objects
Dave Johnson
Re: expected behavior of PF_PACKET on NETIF_F_HW_VLAN_RX device?
linux-netdev
:
Arnd Bergmann
Re: 64-bit net_device_stats
Stephens, Allan
RE: [PATCH]: tipc: Fix oops on send prior to entering networked mode
frank.blaschka
[patch 3/5] [PATCH] qeth: support z/VM VSWITCH Port Isolation
Wu Fengguang
Re: [PATCH] dm9601: handle corrupt mac address
David Miller
Re: [PATCH net-2.6.24] Fix refcounting problem with netif_rx_reschedule()
git
:
Junio C Hamano
Re: [PATCH] [RFC] add Message-ID field to log on git-am operation
Junio C Hamano
Re: Handling large files with GIT
Karl
Re: [ANNOUNCE] pg - A patch porcelain for GIT
Josh Triplett
Re: [RFC][PATCH 00/10] Sparse: Git's "make check" target
Pierre Habouzit
Re: [PATCH] git-daemon: more powerful base-path/user-path settings, using formats.
git-commits-head
:
Linux Kernel Mailing List
MIPS: RBTX4939: Fix IOC pin-enable register updating
Linux Kernel Mailing List
regulator: update email address for Liam Girdwood
Linux Kernel Mailing List
[SCSI] ipr: add message to error table
Linux Kernel Mailing List
powerpc/32: Wire up the trampoline code for kdump
Linux Kernel Mailing List
USB: omap_udc: sync with OMAP tree
openbsd-misc
:
Josh Grosse
Re: error : pkg add phpMyAdmin
Brian Candler
Re: OBSD's perspective on SELinux
Jacob Meuser
Re: /dev/audio: Device busy
David Vasek
Re: Inexpensive, low power, "wall wart" computer
William Boshuck
Re: Richard Stallman...
Colocation donated by:
Syndicate