delphij's Chaos


22 Jan 2004

DragonflyBSD tcp_input.c fix merged!!

Big news! After about four months Jeffrey Hsu has finally merged his fix of RFC3042 to FreeBSD!

I have posted this into the “Security” category because this is a potentially a remote-exploitable security issue. (DoS maxmium).

DragonflyBSD’s rev. 1.10’s log reads:

“Account for when Limited Transmit is not congestion window limited.”

This will fix the potential panic when RFC3042 is enabled. Rev. 1.220 in FreeBSD merges this change.

Jeffrey Hsu is object to the change in 1.219, he said the change is a violation of TCP standard.