Page MenuHomeFreeBSD
Feed Advanced Search

Sep 6 2023

gordon committed rG902c13c4cf68: caroot: add new certs (authored by kevans).
caroot: add new certs
Sep 6 2023, 5:38 PM
gordon committed rG41b7760991ef: pf: handle multiple IPv6 fragment headers (authored by kp).
pf: handle multiple IPv6 fragment headers
Sep 6 2023, 5:38 PM
gordon committed rG927b6e752c24: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Sep 6 2023, 5:38 PM
gordon committed rGe020f9602809: net80211: fail for unicast traffic without unicast key (authored by domienschepers <schepers.d@northeastern.edu>).
net80211: fail for unicast traffic without unicast key
Sep 6 2023, 5:38 PM
gordon committed rGa1c915cc75c1: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Sep 6 2023, 5:38 PM
gordon committed rG7f34ee7cc56b: net80211: fail for unicast traffic without unicast key (authored by domienschepers <schepers.d@northeastern.edu>).
net80211: fail for unicast traffic without unicast key
Sep 6 2023, 5:38 PM

Aug 1 2023

gordon committed R9:80a22168a18d: Update SA-23:04.pam_krb5 with a pointer to SA-23:09.pam_krb5. (authored by gordon).
Update SA-23:04.pam_krb5 with a pointer to SA-23:09.pam_krb5.
Aug 1 2023, 10:48 PM
gordon committed R9:bf75c163e29a: Add EN-23:08 and SA-23:06 through SA-23:09. (authored by gordon).
Add EN-23:08 and SA-23:06 through SA-23:09.
Aug 1 2023, 9:26 PM

Jun 21 2023

gordon committed R9:062b6a21b63e: Add EN-23:05 to EN-23:07, SA-23:04, and SA-23:05. (authored by gordon).
Add EN-23:05 to EN-23:07, SA-23:04, and SA-23:05.
Jun 21 2023, 6:07 AM
gordon committed rGc7b05da29795: mpr: fix copying of event_mask (authored by oshogbo).
mpr: fix copying of event_mask
Jun 21 2023, 5:44 AM
gordon committed rGbc61a15ededc: mpr: fix copying of event_mask (authored by oshogbo).
mpr: fix copying of event_mask
Jun 21 2023, 5:44 AM
gordon committed rG0453667c492c: pam_krb5: Fix spoofing vulnerability (authored by cy).
pam_krb5: Fix spoofing vulnerability
Jun 21 2023, 5:44 AM
gordon committed rGe374f1ec937f: openssh: include destination constraints for smartcard keys (authored by emaste).
openssh: include destination constraints for smartcard keys
Jun 21 2023, 5:44 AM
gordon committed rG07e3f54f2ea1: pam_krb5: Fix spoofing vulnerability (authored by cy).
pam_krb5: Fix spoofing vulnerability
Jun 21 2023, 5:44 AM
gordon committed rGe63d8b8fa6d9: mpr: fix copying of event_mask (authored by oshogbo).
mpr: fix copying of event_mask
Jun 21 2023, 5:44 AM
gordon committed rG5d2bbb9db2d2: loader: comconsole: don't unconditionally wipe out hw.uart.console (authored by kevans).
loader: comconsole: don't unconditionally wipe out hw.uart.console
Jun 21 2023, 5:43 AM
gordon committed rG27340c75ee9f: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Jun 21 2023, 5:43 AM
gordon committed rG548ece23b51c: contrib/tzdata: import tzdata 2023c (authored by gordon).
contrib/tzdata: import tzdata 2023c
Jun 21 2023, 5:43 AM
gordon committed rG58d21e3e8e56: pam_krb5: Fix spoofing vulnerability (authored by cy).
pam_krb5: Fix spoofing vulnerability
Jun 21 2023, 5:43 AM
gordon committed rGdf74c1165cd0: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Jun 21 2023, 5:43 AM
gordon committed rG525ac1948af8: loader: comconsole: don't unconditionally wipe out hw.uart.console (authored by kevans).
loader: comconsole: don't unconditionally wipe out hw.uart.console
Jun 21 2023, 5:43 AM
gordon committed rG0e577c42f61c: contrib/tzdata: import tzdata 2023c (authored by gordon).
contrib/tzdata: import tzdata 2023c
Jun 21 2023, 5:43 AM
gordon committed rG08b87f63a046: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Jun 21 2023, 5:43 AM
gordon committed rG5018f551ece2: pam_krb5: Fix spoofing vulnerability (authored by cy).
pam_krb5: Fix spoofing vulnerability
Jun 21 2023, 5:27 AM
gordon committed rG6322a6c9daaa: pam_krb5: Fix spoofing vulnerability (authored by cy).
pam_krb5: Fix spoofing vulnerability
Jun 21 2023, 5:26 AM
gordon committed rG813847e49e35: pam_krb5: Fix spoofing vulnerability (authored by cy).
pam_krb5: Fix spoofing vulnerability
Jun 21 2023, 5:25 AM

Apr 17 2023

gordon accepted D39618: website/content/en/security/: Add releng/13.2.
Apr 17 2023, 2:44 PM

Mar 20 2023

gordon committed R9:13adb2e1e231: Extend lifetime of my key. (authored by gordon).
Extend lifetime of my key.
Mar 20 2023, 3:39 AM

Mar 2 2023

gordon committed R9:3fa9c9c9032c: Correct the correction detail section. (authored by gordon).
Correct the correction detail section.
Mar 2 2023, 3:24 AM

Feb 27 2023

gordon accepted D38648: ssh: default VerifyHostKeyDNS to no, following upstream.

Looks good to me.

Feb 27 2023, 3:14 PM

Feb 16 2023

gordon committed R9:d11e17c11401: Add SA-23:02 and SA-23:03. (authored by gordon).
Add SA-23:02 and SA-23:03.
Feb 16 2023, 6:15 PM
gordon committed rGe87e8c20e647: ssh: fix double-free caused by compat_kex_proposal() (authored by emaste).
ssh: fix double-free caused by compat_kex_proposal()
Feb 16 2023, 6:03 PM
gordon committed rGc6444607997d: Fix multiple OpenSSL vulnerabilities. (authored by gordon).
Fix multiple OpenSSL vulnerabilities.
Feb 16 2023, 6:02 PM
gordon committed rG149768b65d61: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Feb 16 2023, 6:02 PM
gordon committed rGafb60ed7d8a1: Fix multiple OpenSSL vulnerabilities. (authored by gordon).
Fix multiple OpenSSL vulnerabilities.
Feb 16 2023, 6:02 PM
gordon committed rG7f1c8b021bfe: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Feb 16 2023, 6:02 PM
gordon committed rG00935d2e533c: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Feb 16 2023, 6:02 PM
gordon committed rGe237b128e080: Fix multiple OpenSSL vulnerabilities. (authored by gordon).
Fix multiple OpenSSL vulnerabilities.
Feb 16 2023, 6:02 PM

Feb 8 2023

gordon committed R9:5c437387fc29: Add EN-23:01 to EN-23:04 and SA-23:01. (authored by gordon).
Add EN-23:01 to EN-23:04 and SA-23:01.
Feb 8 2023, 6:59 PM
gordon committed rG52442e904dfc: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Feb 8 2023, 6:30 PM
gordon committed rG256e92061356: geli: split the initalization of HMAC (authored by oshogbo).
geli: split the initalization of HMAC
Feb 8 2023, 6:30 PM
gordon committed rGab78a51c8d2b: contrib/tzdata: import tzdata 2022g (authored by philip).
contrib/tzdata: import tzdata 2022g
Feb 8 2023, 6:30 PM
gordon committed rG36a39f0cc68f: ixgbe: workaround errata about UDP frames with zero checksum (authored by ae).
ixgbe: workaround errata about UDP frames with zero checksum
Feb 8 2023, 6:30 PM
gordon committed rG5e1ad8bebd36: geli: split the initalization of HMAC (authored by oshogbo).
geli: split the initalization of HMAC
Feb 8 2023, 6:28 PM
gordon committed rGf31403bfdd79: ixgbe: workaround errata about UDP frames with zero checksum (authored by ae).
ixgbe: workaround errata about UDP frames with zero checksum
Feb 8 2023, 6:28 PM
gordon committed rGd4745a868116: contrib/tzdata: import tzdata 2022g (authored by philip).
contrib/tzdata: import tzdata 2022g
Feb 8 2023, 6:28 PM
gordon committed rG138c4a1553a1: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Feb 8 2023, 6:28 PM
gordon committed rG98933c7013a5: geli: split the initalization of HMAC (authored by oshogbo).
geli: split the initalization of HMAC
Feb 8 2023, 6:18 PM
gordon committed rG01efaef88f1e: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Feb 8 2023, 6:17 PM
gordon committed rGf3e20eb8d8f0: ixgbe: workaround errata about UDP frames with zero checksum (authored by ae).
ixgbe: workaround errata about UDP frames with zero checksum
Feb 8 2023, 6:17 PM
gordon committed rGb508850e150e: Fix ena driver crash after reset in 7th gen AWS instance types. (authored by gordon).
Fix ena driver crash after reset in 7th gen AWS instance types.
Feb 8 2023, 6:16 PM
gordon committed rG4b31a7861af0: Fix sdhci(4) broken write-protect settings. (authored by gordon).
Fix sdhci(4) broken write-protect settings.
Feb 8 2023, 6:16 PM
gordon committed rG9e3b86743c4b: contrib/tzdata: import tzdata 2022g (authored by philip).
contrib/tzdata: import tzdata 2022g
Feb 8 2023, 6:16 PM
gordon committed rGa5afaf4e9abd: geli: split the initalization of HMAC (authored by oshogbo).
geli: split the initalization of HMAC
Feb 8 2023, 6:05 PM
gordon committed rG88bb08452ee3: geli: split the initalization of HMAC (authored by oshogbo).
geli: split the initalization of HMAC
Feb 8 2023, 6:04 PM
gordon committed rG5fff09660e06: geli: split the initalization of HMAC (authored by oshogbo).
geli: split the initalization of HMAC
Feb 8 2023, 6:03 PM

Jan 6 2023

gordon committed R9:00e5485ee928: Remove the old security officer key that has now expired. (authored by gordon).
Remove the old security officer key that has now expired.
Jan 6 2023, 5:23 PM
gordon committed R9:78158d42f294: Remove the secteam-secretary key and any references to it. (authored by gordon).
Remove the secteam-secretary key and any references to it.
Jan 6 2023, 5:21 PM

Jan 5 2023

gordon committed R9:f29736095d2d: Set the end of life date for 12.3. (authored by gordon).
Set the end of life date for 12.3.
Jan 5 2023, 5:01 PM

Dec 15 2022

gordon committed R9:54313f16d8a8: Update PGP key for security-officer. (authored by gordon).
Update PGP key for security-officer.
Dec 15 2022, 8:02 PM
gordon committed R9:512f2bb33b8b: Update SA-22:15.ping for credit, impact, and a spelling mistake. (authored by gordon).
Update SA-22:15.ping for credit, impact, and a spelling mistake.
Dec 15 2022, 5:53 AM

Nov 29 2022

gordon committed R9:40b6db4afe1f: Add EN-22:28 and SA-22:15. Revise SA-22:14. (authored by gordon).
Add EN-22:28 and SA-22:15. Revise SA-22:14.
Nov 29 2022, 11:38 PM
gordon committed rG4e1a2eb30b78: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Nov 29 2022, 11:19 PM
gordon committed rG4ff214b2f271: heimdal: Fix: Too large time skew, client time 1970-01-01T01:00:00 (authored by cy).
heimdal: Fix: Too large time skew, client time 1970-01-01T01:00:00
Nov 29 2022, 11:19 PM
gordon committed rG1d66ec7d51e9: ping: Fix handling of IP packet sizes (authored by thj).
ping: Fix handling of IP packet sizes
Nov 29 2022, 11:19 PM
gordon committed rG62b8c69d298c: heimdal: Fix: Too large time skew, client time 1970-01-01T01:00:00 (authored by cy).
heimdal: Fix: Too large time skew, client time 1970-01-01T01:00:00
Nov 29 2022, 11:16 PM
gordon committed rGe0cb8021a8e0: ping: Fix handling of IP packet sizes (authored by thj).
ping: Fix handling of IP packet sizes
Nov 29 2022, 11:16 PM
gordon committed rG10571c04c9dd: heimdal: Fix: Too large time skew, client time 1970-01-01T01:00:00 (authored by cy).
heimdal: Fix: Too large time skew, client time 1970-01-01T01:00:00
Nov 29 2022, 11:16 PM
gordon committed rG66c7b53d9516: ping: Fix handling of IP packet sizes (authored by thj).
ping: Fix handling of IP packet sizes
Nov 29 2022, 11:16 PM
gordon committed rG04043434d294: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Nov 29 2022, 11:16 PM
gordon committed rG753d65a19a55: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Nov 29 2022, 11:16 PM
gordon committed rG186f495d4be1: ping: Fix handling of IP packet sizes (authored by thj).
ping: Fix handling of IP packet sizes
Nov 29 2022, 10:57 PM
gordon committed rG94395be05c14: ping: Fix handling of IP packet sizes (authored by thj).
ping: Fix handling of IP packet sizes
Nov 29 2022, 10:57 PM
gordon committed rG46d7b45a267b: ping: Fix handling of IP packet sizes (authored by thj).
ping: Fix handling of IP packet sizes
Nov 29 2022, 10:56 PM
gordon closed D37195: Remote stack corruption in ping (Embargoed).
Nov 29 2022, 10:55 PM
gordon added a comment to D37195: Remote stack corruption in ping (Embargoed).

This will be released today as FreeBSD-SA-22:15.ping and assigned CVE-2022-23093.

Nov 29 2022, 6:13 PM

Nov 16 2022

gordon committed R9:6bc209f5dd7e: Add SA-22:14. (authored by gordon).
Add SA-22:14.
Nov 16 2022, 3:02 AM

Nov 1 2022

gordon committed R9:f9f3f4b9a13c: Add EN-22:21 through EN-22:27. (authored by gordon).
Add EN-22:21 through EN-22:27.
Nov 1 2022, 10:10 PM

Aug 30 2022

gordon committed R9:06e4364bd6f4: Add EN-22:20 and SA-22:13. (authored by gordon).
Add EN-22:20 and SA-22:13.
Aug 30 2022, 11:48 PM

Aug 22 2022

gordon requested changes to D36255: Add revision history section to SA/EN template.

Do we really need a revision history for every EN/SA despite the fact 95% of them will just have the "initial revision"?

Aug 22 2022, 2:59 PM

Aug 9 2022

gordon committed R9:fb32d2e2a06a: Add EN-22:16 to EN-22:19 and SA-22:09 to SA-22:12. (authored by gordon).
Add EN-22:16 to EN-22:19 and SA-22:09 to SA-22:12.
Aug 9 2022, 9:24 PM

Apr 16 2022

gordon accepted D32930: ssh: retire client-side VersionAddendum.

LGTM.

Apr 16 2022, 3:35 AM

Apr 6 2022

gordon committed R9:2bc6ddc2baef: Add EN-22:15 and SA-22:04 through SA-22:08. (authored by gordon).
Add EN-22:15 and SA-22:04 through SA-22:08.
Apr 6 2022, 3:55 AM

Mar 22 2022

gordon committed R9:001229bfed69: Add EN-22:14.tzdata. (authored by gordon).
Add EN-22:14.tzdata.
Mar 22 2022, 4:41 PM
gordon committed rG7dac93b9215e: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Mar 22 2022, 4:27 PM
gordon committed rG862f4476aeb0: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Mar 22 2022, 4:27 PM
gordon committed rG312522780e83: Add UPDATING entries and bump version. (authored by gordon).
Add UPDATING entries and bump version.
Mar 22 2022, 4:27 PM
gordon committed rGaf3096f23b1c: Bump version. (authored by gordon).
Bump version.
Mar 22 2022, 4:27 PM
gordon committed rG3324a4bc8d46: Add UPDATING entry and bump version. (authored by gordon).
Add UPDATING entry and bump version.
Mar 22 2022, 4:54 AM

Mar 21 2022

gordon committed R9:46e96afb730c: Add EN-22:13.zfs. (authored by gordon).
Add EN-22:13.zfs.
Mar 21 2022, 7:13 PM

Mar 16 2022

gordon committed R9:483f1c50d48c: Correct the correction with the correct dates. So they are correct. (authored by gordon).
Correct the correction with the correct dates. So they are correct.
Mar 16 2022, 11:46 PM

Mar 15 2022

gordon committed R9:5fcaa3b6694f: Fix typos. (authored by gordon).
Fix typos.
Mar 15 2022, 11:58 PM
gordon committed R9:14689b295e29: Update EN-22:11 with revised information. (authored by gordon).
Update EN-22:11 with revised information.
Mar 15 2022, 11:41 PM
gordon committed R9:ba3b824455f8: Add EN-22:09 to EN-22:12 and SA-22:02 to SA-22:03. (authored by gordon).
Add EN-22:09 to EN-22:12 and SA-22:02 to SA-22:03.
Mar 15 2022, 7:22 PM
gordon committed rG942b5e156d41: Fix a bug in BN_mod_sqrt() that can cause it to loop forever. (authored by gordon).
Fix a bug in BN_mod_sqrt() that can cause it to loop forever.
Mar 15 2022, 5:55 PM
gordon committed rGc2a7d6e643bb: Fix a bug in BN_mod_sqrt() that can cause it to loop forever. (authored by gordon).
Fix a bug in BN_mod_sqrt() that can cause it to loop forever.
Mar 15 2022, 4:55 PM
gordon committed rG5f3d952f6e6b: Fix a bug in BN_mod_sqrt() that can cause it to loop forever. (authored by gordon).
Fix a bug in BN_mod_sqrt() that can cause it to loop forever.
Mar 15 2022, 4:53 PM
gordon committed rGfdc418f15e92: Fix a bug in BN_mod_sqrt() that can cause it to loop forever. (authored by gordon).
Fix a bug in BN_mod_sqrt() that can cause it to loop forever.
Mar 15 2022, 4:51 PM
gordon committed R11:8a69b006842f: mail/imapsync: Update 1.977 -> 2.178. (authored by gordon).
mail/imapsync: Update 1.977 -> 2.178.
Mar 15 2022, 3:49 PM

Feb 1 2022

gordon committed R9:f791736fc117: Add EN-22:07 and EN-22:08. (authored by gordon).
Add EN-22:07 and EN-22:08.
Feb 1 2022, 8:11 PM