{"thread":{"id":"10901","subject":"Fwd: [postmaster@vger.kernel.org: Delivery reports about your email [FAILED(1)]]","startedAt":"2007-11-16T18:35:30Z","lastAt":"2007-11-17T09:06:34Z","messageCount":2,"participants":["Matti Aarnio","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"60102","messageId":"20071116183530.GI6372@mea-ext.zmailer.org","threadId":"10901","inReplyTo":null,"subject":"Fwd: [postmaster@vger.kernel.org: Delivery reports about your email [FAILED(1)]]","fromName":"Matti Aarnio","fromEmail":"matti.aarnio@zmailer.org","sentAt":"2007-11-16T18:35:30Z","receivedAt":"2007-11-16T18:35:30Z","isPatch":false,"sender":{"key":"matti.aarnio@zmailer.org","avatar":null},"body":"Here is a sample message that NEEDS proper charset mime tags.\n\n\n\nThis is a collection of reports about email delivery\nprocess concerning a message you originated.\n\nSome explanations/translations for these reports\ncan be found at:\n      http://www.zmailer.org/delivery-report-decoding.html\n\nGeneric VGER note:  Joining/leaving VGER's lists thru server:\n\t\t\tmajordomo@vger.kernel.org\n\nReporting-MTA: dns; vger.kernel.org\nReturn-Path: <stable-commits-owner@vger.kernel.org>\nArrival-Date: Fri, 16 Nov 2007 13:09:40 -0500\nLocal-Spool-ID: S1751399AbXKPSJk\n\n\nFAILED:\n  Original Recipient:\n      rfc822;jfunk@funktronics.ca\n  Final Recipient:\n      RFC822;jfunk@funktronics.ca\n  Status:\n      5.1.1 (bad destination mailbox)\n  Remote MTA:\n      dns; elseed.funktronics.ca (65.61.206.36|25|209.132.176.167|48741)\n  Last Attempt Date:\n      Fri, 16 Nov 2007 13:10:02 -0500\n  X-ZTAID:\n      smtp[6139]\n  Diagnostic Code:\n      smtp; 550 (Error: improper use of 8-bit data in message body)\n  Control data:\n      smtp funktronics.ca jfunk@funktronics.ca 99\n  Diagnostic texts:\n      <<- MAIL From:<stable-commits-owner@vger.kernel.org> BODY=8BITMIME SIZE=3712\n     ->> 250 Ok\n     <<- RCPT To:<jfunk@funktronics.ca>\n     ->> 250 Ok\n     <<- DATA\n     ->> 354 End data with <CR><LF>.<CR><LF>\n     <<- .\n     ->> 550 Error: improper use of 8-bit data in message body\n\nFollowing is a copy of MESSAGE/DELIVERY-STATUS format section below.\nIt is copied here in case your email client is unable to show it to you.\nThe information here below is in  Internet Standard  format designed to\nassist automatic, and accurate presentation and usage of said information.\nIn case you need human assistance from the Postmaster(s) of the system which\nsent you this report, please include this information in your question!\n\n    Virtually Yours,\n        Automatic Email Delivery Software\n\nReporting-MTA: dns; vger.kernel.org\nArrival-Date: Fri, 16 Nov 2007 13:09:40 -0500\nLocal-Spool-ID: S1751399AbXKPSJk\n\nOriginal-Recipient: rfc822;jfunk@funktronics.ca\nFinal-Recipient: RFC822;jfunk@funktronics.ca\nAction: failed\nStatus: 5.1.1 (bad destination mailbox)\nRemote-MTA: dns; elseed.funktronics.ca (65.61.206.36|25|209.132.176.167|48741)\nLast-Attempt-Date: Fri, 16 Nov 2007 13:10:02 -0500\nDiagnostic-Code: smtp; 550 (Error: improper use of 8-bit data in message body)\n\n\nFollowing is copy of the message headers. Original message content may\nbe in subsequent parts of this MESSAGE/DELIVERY-STATUS structure.\n\nReceived: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand\n\tid S1751399AbXKPSJk; Fri, 16 Nov 2007 13:09:40 -0500\nReceived: (majordomo@vger.kernel.org) by vger.kernel.org id S1756649AbXKPSJk\n\t(ORCPT <rfc822;stable-commits-outgoing>);\n\tFri, 16 Nov 2007 13:09:40 -0500\nReceived: from ns2.suse.de ([195.135.220.15]:33829 \"EHLO mx2.suse.de\"\n\trhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP\n\tid S1751399AbXKPSJj (ORCPT <rfc822;stable-commits@vger.kernel.org>);\n\tFri, 16 Nov 2007 13:09:39 -0500\nReceived: from Relay2.suse.de (mail2.suse.de [195.135.221.8])\n\t(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))\n\t(No client certificate requested)\n\tby mx2.suse.de (Postfix) with ESMTP id 142E02BDB9;\n\tFri, 16 Nov 2007 19:09:38 +0100 (CET)\nSubject: patch tcp-make-sure-write_queue_from-does-not-begin-with-null-ptr.patch queued to -stable tree\nTo:\tilpo.jarvinen@helsinki.fi, davem@davemloft.net\nCc:\t<stable@kernel.org>, <stable-commits@vger.kernel.org>\nFrom:\t<gregkh@suse.de>\nDate:\tFri, 16 Nov 2007 10:08:58 -0800\nMessage-Id: <20071116180937.250A0144AB0C@imap.suse.de>\nSender:\tstable-commits-owner@vger.kernel.org\nPrecedence: bulk\nReply-To: linux-kernel@vger.kernel.org\nX-Mailing-List:\tstable-commits@vger.kernel.org\n\n\n\n\n\n\n\n\nThis is a note to let you know that we have just queued up the patch titled\n\n     Subject: TCP: Make sure write_queue_from does not begin with NULL ptr (CVE-2007-5501)\n\nto the 2.6.23-stable tree.  Its filename is\n\n     tcp-make-sure-write_queue_from-does-not-begin-with-null-ptr.patch\n\nA git repo of this tree can be found at \n    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary\n\n\n>From 96a2d41a3e495734b63bff4e5dd0112741b93b38 Mon Sep 17 00:00:00 2001\nFrom: Ilpo J�rvinen <ilpo.jarvinen@helsinki.fi>\nDate: Wed, 14 Nov 2007 15:47:18 -0800\nSubject: TCP: Make sure write_queue_from does not begin with NULL ptr (CVE-2007-5501)\n\nFrom: Ilpo J�rvinen <ilpo.jarvinen@helsinki.fi>\npatch 96a2d41a3e495734b63bff4e5dd0112741b93b38 in mainline.\n\nNULL ptr can be returned from tcp_write_queue_head to cached_skb\nand then assigned to skb if packets_out was zero. Without this,\nsystem is vulnerable to a carefully crafted ACKs which obviously\nis remotely triggerable.\n\nBesides, there's very little that needs to be done in sacktag\nif there weren't any packets outstanding, just skipping the rest\ndoesn't hurt.\n\nSigned-off-by: Ilpo J�rvinen <ilpo.jarvinen@helsinki.fi>\nSigned-off-by: David S. Miller <davem@davemloft.net>\n\n---\n net/ipv4/tcp_input.c |    5 +++++\n 1 file changed, 5 insertions(+)\n\n--- a/net/ipv4/tcp_input.c\n+++ b/net/ipv4/tcp_input.c\n@@ -1012,6 +1012,9 @@ tcp_sacktag_write_queue(struct sock *sk,\n \tif (before(TCP_SKB_CB(ack_skb)->ack_seq, prior_snd_una - tp->max_window))\n \t\treturn 0;\n \n+\tif (!tp->packets_out)\n+\t\tgoto out;\n+\n \t/* SACK fastpath:\n \t * if the only SACK change is the increase of the end_seq of\n \t * the first block then only apply that SACK block\n@@ -1280,6 +1283,8 @@ tcp_sacktag_write_queue(struct sock *sk,\n \t    (!tp->frto_highmark || after(tp->snd_una, tp->frto_highmark)))\n \t\ttcp_update_reordering(sk, ((tp->fackets_out + 1) - reord), 0);\n \n+out:\n+\n #if FASTRETRANS_DEBUG > 0\n \tBUG_TRAP((int)tp->sacked_out >= 0);\n \tBUG_TRAP((int)tp->lost_out >= 0);\n\n\nPatches currently in stable-queue which might be from ilpo.jarvinen@helsinki.fi are\n\nqueue-2.6.23/tcp-make-sure-write_queue_from-does-not-begin-with-null-ptr.patch\n-\nTo unsubscribe from this list: send the line \"unsubscribe stable-commits\" in\nthe body of a message to majordomo@vger.kernel.org\nMore majordomo info at  http://vger.kernel.org/majordomo-info.html"},{"id":"60127","messageId":"20071117090634.GA22352@sigill.intra.peff.net","threadId":"10901","inReplyTo":"20071116183530.GI6372@mea-ext.zmailer.org","subject":"Re: Fwd: [postmaster@vger.kernel.org: Delivery reports about your email [FAILED(1)]]","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2007-11-17T09:06:34Z","receivedAt":"2007-11-17T09:06:34Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Nov 16, 2007 at 08:35:30PM +0200, Matti Aarnio wrote:\n\n> Here is a sample message that NEEDS proper charset mime tags.\n\nThank you for posting a complete example.\n\nHowever, I'm not sure that git is to blame here. The problem text seems\nto be \"Ilpo J�rvinen <ilpo.jarvinen@helsinki.fi>\". However, that text\nseems to be included in a regular mail sent by gregkh. I see no evidence\nof git-send-email being used (neither an X-Mailer, nor any message-id\nwhich would have been generated by it).\n\nIt looks like the culprit is whatever he is using to generate the\nstable-commit response. I'll note a few things below (sorry, the quoting\nis long, but I don't want to omit any details):\n\n> Following is copy of the message headers. Original message content may\n> be in subsequent parts of this MESSAGE/DELIVERY-STATUS structure.\n> \n> Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand\n> \tid S1751399AbXKPSJk; Fri, 16 Nov 2007 13:09:40 -0500\n> Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1756649AbXKPSJk\n> \t(ORCPT <rfc822;stable-commits-outgoing>);\n> \tFri, 16 Nov 2007 13:09:40 -0500\n> Received: from ns2.suse.de ([195.135.220.15]:33829 \"EHLO mx2.suse.de\"\n> \trhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP\n> \tid S1751399AbXKPSJj (ORCPT <rfc822;stable-commits@vger.kernel.org>);\n> \tFri, 16 Nov 2007 13:09:39 -0500\n> Received: from Relay2.suse.de (mail2.suse.de [195.135.221.8])\n> \t(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))\n> \t(No client certificate requested)\n> \tby mx2.suse.de (Postfix) with ESMTP id 142E02BDB9;\n> \tFri, 16 Nov 2007 19:09:38 +0100 (CET)\n> Subject: patch tcp-make-sure-write_queue_from-does-not-begin-with-null-ptr.patch queued to -stable tree\n> To:\tilpo.jarvinen@helsinki.fi, davem@davemloft.net\n> Cc:\t<stable@kernel.org>, <stable-commits@vger.kernel.org>\n> From:\t<gregkh@suse.de>\n> Date:\tFri, 16 Nov 2007 10:08:58 -0800\n> Message-Id: <20071116180937.250A0144AB0C@imap.suse.de>\n> Sender:\tstable-commits-owner@vger.kernel.org\n> Precedence: bulk\n> Reply-To: linux-kernel@vger.kernel.org\n> X-Mailing-List:\tstable-commits@vger.kernel.org\n\nThis is presumably the complete header for the rejected message. I agree\nthis ought to have a content-type header, but it clearly wasn't sent by\ngit-send-email.\n\nPresumably there is some post-receive hook that is doing this, but it's\nhard to say more without seeing the hook.\n\n> Reporting-MTA: dns; vger.kernel.org\n> Arrival-Date: Fri, 16 Nov 2007 13:09:40 -0500\n> Local-Spool-ID: S1751399AbXKPSJk\n> \n> Original-Recipient: rfc822;jfunk@funktronics.ca\n> Final-Recipient: RFC822;jfunk@funktronics.ca\n> Action: failed\n> Status: 5.1.1 (bad destination mailbox)\n> Remote-MTA: dns; elseed.funktronics.ca (65.61.206.36|25|209.132.176.167|48741)\n> Last-Attempt-Date: Fri, 16 Nov 2007 13:10:02 -0500\n> Diagnostic-Code: smtp; 550 (Error: improper use of 8-bit data in message body)\n\n> Date: Fri, 16 Nov 2007 10:08:58 -0800\n> From: gregkh@suse.de\n> To: ilpo.jarvinen@helsinki.fi, davem@davemloft.net\n> Cc: stable@kernel.org, stable-commits@vger.kernel.org\n> Reply-To: linux-kernel@vger.kernel.org\n> Subject: patch\n> \ttcp-make-sure-write_queue_from-does-not-begin-with-null-ptr.patch\n> \tqueued to -stable tree\n> \n> \n> This is a note to let you know that we have just queued up the patch titled\n> \n>      Subject: TCP: Make sure write_queue_from does not begin with NULL ptr (CVE-2007-5501)\n> \n> to the 2.6.23-stable tree.  Its filename is\n> \n>      tcp-make-sure-write_queue_from-does-not-begin-with-null-ptr.patch\n> \n> A git repo of this tree can be found at \n>     http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary\n> \n> \n> >From 96a2d41a3e495734b63bff4e5dd0112741b93b38 Mon Sep 17 00:00:00 2001\n> From: Ilpo J�rvinen <ilpo.jarvinen@helsinki.fi>\n> Date: Wed, 14 Nov 2007 15:47:18 -0800\n> Subject: TCP: Make sure write_queue_from does not begin with NULL ptr (CVE-2007-5501)\n> \n> From: Ilpo J�rvinen <ilpo.jarvinen@helsinki.fi>\n\nAnd this is clearly generated by git-format-patch. The signed-off-by\nrequires a charset specifier. This was fixed by Junio in 4593fb84 about\n2 weeks ago, but hasn't made it into a released version yet.\n\nThe extra 'From' line in the body of the email is not something\ngenerated by git-format-patch. Usually such lines are placed by\ngit-send-email, and would require encoding; we just queued a fix for\nthat yesterday. However, I don't see any other evidence of\ngit-send-email being used here, so it looks more like whatever script\ngenerated the outer mail just called git-format-patch.\n\n> patch 96a2d41a3e495734b63bff4e5dd0112741b93b38 in mainline.\n> \n> NULL ptr can be returned from tcp_write_queue_head to cached_skb\n> and then assigned to skb if packets_out was zero. Without this,\n> system is vulnerable to a carefully crafted ACKs which obviously\n> is remotely triggerable.\n> \n> Besides, there's very little that needs to be done in sacktag\n> if there weren't any packets outstanding, just skipping the rest\n> doesn't hurt.\n> \n> Signed-off-by: Ilpo J�rvinen <ilpo.jarvinen@helsinki.fi>\n> Signed-off-by: David S. Miller <davem@davemloft.net>\n> \n> ---\n>  net/ipv4/tcp_input.c |    5 +++++\n>  1 file changed, 5 insertions(+)\n> \n> --- a/net/ipv4/tcp_input.c\n> +++ b/net/ipv4/tcp_input.c\n> @@ -1012,6 +1012,9 @@ tcp_sacktag_write_queue(struct sock *sk,\n>  \tif (before(TCP_SKB_CB(ack_skb)->ack_seq, prior_snd_una - tp->max_window))\n>  \t\treturn 0;\n>  \n> +\tif (!tp->packets_out)\n> +\t\tgoto out;\n> +\n>  \t/* SACK fastpath:\n>  \t * if the only SACK change is the increase of the end_seq of\n>  \t * the first block then only apply that SACK block\n> @@ -1280,6 +1283,8 @@ tcp_sacktag_write_queue(struct sock *sk,\n>  \t    (!tp->frto_highmark || after(tp->snd_una, tp->frto_highmark)))\n>  \t\ttcp_update_reordering(sk, ((tp->fackets_out + 1) - reord), 0);\n>  \n> +out:\n> +\n>  #if FASTRETRANS_DEBUG > 0\n>  \tBUG_TRAP((int)tp->sacked_out >= 0);\n>  \tBUG_TRAP((int)tp->lost_out >= 0);\n> \n> \n> Patches currently in stable-queue which might be from ilpo.jarvinen@helsinki.fi are\n> \n> queue-2.6.23/tcp-make-sure-write_queue_from-does-not-begin-with-null-ptr.patch\n> -\n> To unsubscribe from this list: send the line \"unsubscribe stable-commits\" in\n> the body of a message to majordomo@vger.kernel.org\n> More majordomo info at  http://vger.kernel.org/majordomo-info.html\n"}]}