All of lore.kernel.org
 help / color / mirror / Atom feed
* Security support status of xnf(4) and xbf(4)
@ 2022-03-25 16:13 Demi Marie Obenour
  2022-03-25 22:42 ` Chris Cappuccio
  2022-03-28  1:45 ` Damien Miller
  0 siblings, 2 replies; 14+ messages in thread
From: Demi Marie Obenour @ 2022-03-25 16:13 UTC (permalink / raw)
  To: Roger Pau Monné, Marek Marczykowski-Górecki
  Cc: Xen developer discussion, OpenBSD technical mailing list

[-- Attachment #1: Type: text/plain, Size: 1010 bytes --]

Linux’s netfront and blkfront drivers recently had a security
vulnerability (XSA-396) that allowed a malicious backend to potentially
compromise them.  In follow-up audits, I found that OpenBSD’s xnf(4)
currently trusts the backend domain.  I reported this privately to Theo
de Raadt, who indicated that OpenBSD does not consider this to be a
security concern.

This is obviously a valid position for the OpenBSD project to take, but
it is surprising to some (such as myself) from the broader Xen
ecosystem.  Standard practice in the Xen world is that bugs in frontends
that allow a malicious backend to cause mischief *are* considered
security bugs unless there is explicit documentation to the contrary.
As such, I believe this deserves to be noted in xnf(4) and xbf(4)’s man
pages.  If the OpenBSD project agrees, I am willing to write a patch,
but I have no experience with mandoc so it might take a few tries.
-- 
Sincerely,
Demi Marie Obenour (she/her/hers)
Invisible Things Lab

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2022-03-29 16:22 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2022-03-25 16:13 Security support status of xnf(4) and xbf(4) Demi Marie Obenour
2022-03-25 22:42 ` Chris Cappuccio
2022-03-25 23:09   ` Demi Marie Obenour
2022-03-25 23:50   ` Andrew Cooper
2022-03-28  1:45 ` Damien Miller
2022-03-28  2:12   ` Marek Marczykowski-Górecki
2022-03-28  2:13     ` Marek Marczykowski-Górecki
2022-03-28 13:51   ` Demi Marie Obenour
2022-03-28 14:39     ` Mark Kettenis
2022-03-28 20:38       ` Demi Marie Obenour
2022-03-28 23:42         ` Theo de Raadt
2022-03-29  8:16         ` Claudio Jeker
2022-03-29 10:51           ` Roger Pau Monné
2022-03-29 16:22           ` Demi Marie Obenour

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.