Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

That's one small step for a man; one giant leap for mankind. -- Neil Armstrong


computers / comp.os.vms / Re: DECNet support dropped from Linux kernel

SubjectAuthor
* DECNet support dropped from Linux kernelScott Dorsey
+- Re: DECNet support dropped from Linux kernelJohn Forecast
+* Re: DECNet support dropped from Linux kernelArne Vajhøj
|`- Re: DECNet support dropped from Linux kernelgah4
+- Re: DECNet support dropped from Linux kernelSimon Clubley
`* Re: DECNet support dropped from Linux kernelDave McGuire
 +- Re: DECNet support dropped from Linux kernelBob Eager
 `- Re: DECNet support dropped from Linux kernelJake Hamby (Solid State Jake)

1
DECNet support dropped from Linux kernel

<ufpc1h$cql$1@panix2.panix.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=30357&group=comp.os.vms#30357

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!panix!.POSTED.panix2.panix.com!panix2.panix.com!not-for-mail
From: klu...@panix.com (Scott Dorsey)
Newsgroups: comp.os.vms
Subject: DECNet support dropped from Linux kernel
Date: 6 Oct 2023 16:18:57 -0000
Organization: Former users of Netcom shell (1989-2000)
Lines: 13
Message-ID: <ufpc1h$cql$1@panix2.panix.com>
Injection-Info: reader2.panix.com; posting-host="panix2.panix.com:166.84.1.2";
logging-data="27735"; mail-complaints-to="abuse@panix.com"
 by: Scott Dorsey - Fri, 6 Oct 2023 16:18 UTC

Just looking at this week's list of kernel updates and noticed this very
interesting item tucked in there:

Davide Ornaghi discovered that the DECnet network protocol implementation
in the Linux kernel contained a null pointer dereference vulnerability. A
remote attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. Please note that kernel support for the
DECnet has been removed to resolve this CVE. (CVE-2023-3338)

I can't tell if this is a good or a bad thing.
--scott
--
"C'est un Nagra. C'est suisse, et tres, tres precis."

Re: DECNet support dropped from Linux kernel

<0001HW.2AD071C30009C6EC70000AB7538F@news80.forteinc.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=30358&group=comp.os.vms#30358

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!feeder1-2.proxad.net!proxad.net!feeder1-1.proxad.net!193.141.40.65.MISMATCH!npeer.as286.net!npeer-ng0.as286.net!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx36.iad.POSTED!not-for-mail
From: johnfore...@comcast.net (John Forecast)
Mime-Version: 1.0
User-Agent: Hogwasher/5.24
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
Message-ID: <0001HW.2AD071C30009C6EC70000AB7538F@news80.forteinc.com>
Subject: Re: DECNet support dropped from Linux kernel
Newsgroups: comp.os.vms
X-No-Archive: yes
References: <ufpc1h$cql$1@panix2.panix.com>
Lines: 22
X-Complaints-To: abuse@easynews.com
Organization: Forte - www.forteinc.com
X-Complaints-Info: Please be sure to forward a copy of ALL headers otherwise we will be unable to process your complaint properly.
Date: Fri, 06 Oct 2023 12:48:03 -0400
X-Received-Bytes: 1521
 by: John Forecast - Fri, 6 Oct 2023 16:48 UTC

On Oct 6, 2023, Scott Dorsey wrote
(in article <ufpc1h$cql$1@panix2.panix.com>):

> Just looking at this week's list of kernel updates and noticed this very
> interesting item tucked in there:
>
> Davide Ornaghi discovered that the DECnet network protocol implementation
> in the Linux kernel contained a null pointer dereference vulnerability. A
> remote attacker could use this to cause a denial of service (system crash)
> or possibly execute arbitrary code. Please note that kernel support for the
> DECnet has been removed to resolve this CVE. (CVE-2023-3338)
>
> I can't tell if this is a good or a bad thing.
> --scott

The DECnet protocol was removed from all forward development starting with
with Kernel 6.1.x. This appears to be the removal from long term support
kernels.

John.

Re: DECNet support dropped from Linux kernel

<ufpee0$1ksgb$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=30359&group=comp.os.vms#30359

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!rocksolid2!news.neodome.net!news.mixmin.net!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: arn...@vajhoej.dk (Arne Vajhøj)
Newsgroups: comp.os.vms
Subject: Re: DECNet support dropped from Linux kernel
Date: Fri, 6 Oct 2023 12:59:43 -0400
Organization: A noiseless patient Spider
Lines: 20
Message-ID: <ufpee0$1ksgb$1@dont-email.me>
References: <ufpc1h$cql$1@panix2.panix.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 6 Oct 2023 16:59:44 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="0b5c19b0184fb33d23f3495487d56f47";
logging-data="1733131"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/ZnFzhQPOE5HKVrKCpeP1i/DSyyQENFj0="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:H1ELxi2ifI+tr/j5wIMjyHxxQcU=
In-Reply-To: <ufpc1h$cql$1@panix2.panix.com>
Content-Language: en-US
 by: Arne Vajhøj - Fri, 6 Oct 2023 16:59 UTC

On 10/6/2023 12:18 PM, Scott Dorsey wrote:
> Just looking at this week's list of kernel updates and noticed this very
> interesting item tucked in there:
>
> Davide Ornaghi discovered that the DECnet network protocol implementation
> in the Linux kernel contained a null pointer dereference vulnerability. A
> remote attacker could use this to cause a denial of service (system crash)
> or possibly execute arbitrary code. Please note that kernel support for the
> DECnet has been removed to resolve this CVE. (CVE-2023-3338)
>
> I can't tell if this is a good or a bad thing.

Probably an insignificant thing.

There may still be a big part of VMS users that use DECnet
for VMS - VMS comm, but I cannot imagine many using DECnet
for VMS - Linux comm.

Arne

Re: DECNet support dropped from Linux kernel

<ufph5e$1lfbv$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=30361&group=comp.os.vms#30361

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: club...@remove_me.eisner.decus.org-Earth.UFP (Simon Clubley)
Newsgroups: comp.os.vms
Subject: Re: DECNet support dropped from Linux kernel
Date: Fri, 6 Oct 2023 17:46:22 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 29
Message-ID: <ufph5e$1lfbv$1@dont-email.me>
References: <ufpc1h$cql$1@panix2.panix.com>
Injection-Date: Fri, 6 Oct 2023 17:46:22 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="36dceb741f288de8ea5c66dd358f522c";
logging-data="1752447"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/SNyuYJS2AbZA1qJ2BRdeZYulzNzBjEGU="
User-Agent: slrn/0.9.8.1 (VMS/Multinet)
Cancel-Lock: sha1:PZ3rpFa4IpKApGCHk4VzIYZ8cnk=
 by: Simon Clubley - Fri, 6 Oct 2023 17:46 UTC

On 2023-10-06, Scott Dorsey <kludge@panix.com> wrote:
> Just looking at this week's list of kernel updates and noticed this very
> interesting item tucked in there:
>
> Davide Ornaghi discovered that the DECnet network protocol implementation
> in the Linux kernel contained a null pointer dereference vulnerability. A
> remote attacker could use this to cause a denial of service (system crash)
> or possibly execute arbitrary code. Please note that kernel support for the
> DECnet has been removed to resolve this CVE. (CVE-2023-3338)
>
> I can't tell if this is a good or a bad thing.

Removing it is a very good thing. The sooner all trace of that protocol
is removed from everything, especially in today's security environment,
the better.

BTW, as a reminder, these are the, erm, "strange" features I found in the
VMS DECnet stack when I gave it a quick inspection a couple of years ago:

https://groups.google.com/g/comp.os.vms/c/Bjp0hRkSnh4

I never heard anything final back from VSI, so I don't know if they have
fixed any of them.

Simon.

--
Simon Clubley, clubley@remove_me.eisner.decus.org-Earth.UFP
Walking destinations on a map are further away than they appear.

Re: DECNet support dropped from Linux kernel

<8e1b7728-4a87-4141-adde-8d830c91b115n@googlegroups.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=30372&group=comp.os.vms#30372

  copy link   Newsgroups: comp.os.vms
X-Received: by 2002:a05:622a:1809:b0:410:a249:bee5 with SMTP id t9-20020a05622a180900b00410a249bee5mr128409qtc.9.1696626817688;
Fri, 06 Oct 2023 14:13:37 -0700 (PDT)
X-Received: by 2002:a9d:7ad6:0:b0:6b9:5156:a493 with SMTP id
m22-20020a9d7ad6000000b006b95156a493mr2869243otn.4.1696626817553; Fri, 06 Oct
2023 14:13:37 -0700 (PDT)
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!proxad.net!feeder1-2.proxad.net!209.85.160.216.MISMATCH!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.os.vms
Date: Fri, 6 Oct 2023 14:13:36 -0700 (PDT)
In-Reply-To: <ufpee0$1ksgb$1@dont-email.me>
Injection-Info: google-groups.googlegroups.com; posting-host=2601:602:9700:4689:4563:6b51:d63c:fe98;
posting-account=gLDX1AkAAAA26M5HM-O3sVMAXdxK9FPA
NNTP-Posting-Host: 2601:602:9700:4689:4563:6b51:d63c:fe98
References: <ufpc1h$cql$1@panix2.panix.com> <ufpee0$1ksgb$1@dont-email.me>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <8e1b7728-4a87-4141-adde-8d830c91b115n@googlegroups.com>
Subject: Re: DECNet support dropped from Linux kernel
From: gah...@u.washington.edu (gah4)
Injection-Date: Fri, 06 Oct 2023 21:13:37 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
 by: gah4 - Fri, 6 Oct 2023 21:13 UTC

On Friday, October 6, 2023 at 9:59:48 AM UTC-7, Arne Vajhøj wrote:

(snip)

> There may still be a big part of VMS users that use DECnet
> for VMS - VMS comm, but I cannot imagine many using DECnet
> for VMS - Linux comm.

There might be some compuarchaologists (that is, people running
ancient computers) out there. They will be happy to run the older
versions of Linux.

Likely on their 80486 host and 10 megabit Ethernet.

Re: DECNet support dropped from Linux kernel

<uigd1d$149b$1@mail.neurotica.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=31061&group=comp.os.vms#31061

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!paganini.bofh.team!news.killfile.org!news.eyrie.org!news.xcski.com!news.neurotica.com!.POSTED.gw.neurotica.com!not-for-mail
From: mcgu...@lssmuseum.org (Dave McGuire)
Newsgroups: comp.os.vms
Subject: Re: DECNet support dropped from Linux kernel
Date: Wed, 8 Nov 2023 11:29:33 -0500
Organization: LSSM
Message-ID: <uigd1d$149b$1@mail.neurotica.com>
References: <ufpc1h$cql$1@panix2.panix.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 8 Nov 2023 16:29:33 -0000 (UTC)
Injection-Info: mail.neurotica.com; posting-host="gw.neurotica.com:50.73.179.1";
logging-data="37163"; mail-complaints-to="usenet@mail.neurotica.com"
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101
Thunderbird/102.13.0
Content-Language: en-US
In-Reply-To: <ufpc1h$cql$1@panix2.panix.com>
 by: Dave McGuire - Wed, 8 Nov 2023 16:29 UTC

On 10/6/23 12:18, Scott Dorsey wrote:
> Just looking at this week's list of kernel updates and noticed this very
> interesting item tucked in there:
>
> Davide Ornaghi discovered that the DECnet network protocol implementation
> in the Linux kernel contained a null pointer dereference vulnerability. A
> remote attacker could use this to cause a denial of service (system crash)
> or possibly execute arbitrary code. Please note that kernel support for the
> DECnet has been removed to resolve this CVE. (CVE-2023-3338)
>
> I can't tell if this is a good or a bad thing.

It was, of course, a bad thing.

But the problem has been addressed. John Forecast has released his
DECnet for Linux stack, based on the original, with a great many fixes,
and many changes to reduce its dependency on moving-target kernel APIs.

https://github.com/JohnForecast/LinuxDECnet

We're testing it here, and so far it works well, and not on ancient
Linux. We're testing it with Ubuntu 22.04 in a VM under SmartOS.

-Dave

--
Dave McGuire, President/Curator
Large Scale Systems Museum
New Kensington, PA

Re: DECNet support dropped from Linux kernel

<kr1v36Fpj8tU10@mid.individual.net>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=31062&group=comp.os.vms#31062

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: news0...@eager.cx (Bob Eager)
Newsgroups: comp.os.vms
Subject: Re: DECNet support dropped from Linux kernel
Date: 8 Nov 2023 17:33:27 GMT
Lines: 29
Message-ID: <kr1v36Fpj8tU10@mid.individual.net>
References: <ufpc1h$cql$1@panix2.panix.com>
<uigd1d$149b$1@mail.neurotica.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net nGNvr3FnLXurkM5J6TevGgd7ER3/Jj0fE+XerOxE2xhWwsNkst
Cancel-Lock: sha1:IzAKF7IlDTGgTuAriZ/r1TeGjdM= sha256:T6XWubfyBpazA9e/3FJw7RNhILKjmukUzTqCQu9gVoU=
User-Agent: Pan/0.145 (Duplicitous mercenary valetism; d7e168a
git.gnome.org/pan2)
 by: Bob Eager - Wed, 8 Nov 2023 17:33 UTC

On Wed, 08 Nov 2023 11:29:33 -0500, Dave McGuire wrote:

> On 10/6/23 12:18, Scott Dorsey wrote:
>> Just looking at this week's list of kernel updates and noticed this
>> very interesting item tucked in there:
>>
>> Davide Ornaghi discovered that the DECnet network protocol
>> implementation in the Linux kernel contained a null pointer dereference
>> vulnerability. A remote attacker could use this to cause a denial of
>> service (system crash) or possibly execute arbitrary code. Please note
>> that kernel support for the DECnet has been removed to resolve this
>> CVE. (CVE-2023-3338)
>>
>> I can't tell if this is a good or a bad thing.
>
> It was, of course, a bad thing.
>
> But the problem has been addressed. John Forecast has released his
> DECnet for Linux stack, based on the original, with a great many fixes,
> and many changes to reduce its dependency on moving-target kernel APIs.
>
> https://github.com/JohnForecast/LinuxDECnet
>
> We're testing it here, and so far it works well, and not on ancient
> Linux. We're testing it with Ubuntu 22.04 in a VM under SmartOS.

John Forecast! A name from the past! I met him at Essex University in
1974, and was later able to help him by giving him a copy of his own
source code from his Ph.D.

Re: DECNet support dropped from Linux kernel

<4111d529-3bff-4ce8-abfa-6dcaec7c9e1bn@googlegroups.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=31063&group=comp.os.vms#31063

  copy link   Newsgroups: comp.os.vms
X-Received: by 2002:a05:620a:1a03:b0:773:f2a0:fda5 with SMTP id bk3-20020a05620a1a0300b00773f2a0fda5mr49315qkb.4.1699470107545;
Wed, 08 Nov 2023 11:01:47 -0800 (PST)
X-Received: by 2002:a05:6870:2423:b0:1e9:a86f:ec3b with SMTP id
n35-20020a056870242300b001e9a86fec3bmr1076228oap.2.1699470107216; Wed, 08 Nov
2023 11:01:47 -0800 (PST)
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.os.vms
Date: Wed, 8 Nov 2023 11:01:46 -0800 (PST)
In-Reply-To: <uigd1d$149b$1@mail.neurotica.com>
Injection-Info: google-groups.googlegroups.com; posting-host=2600:1700:46b0:abc0:9590:b268:23bf:103;
posting-account=OGFVHQoAAAASiNAamRQec8BtkuXxYFnQ
NNTP-Posting-Host: 2600:1700:46b0:abc0:9590:b268:23bf:103
References: <ufpc1h$cql$1@panix2.panix.com> <uigd1d$149b$1@mail.neurotica.com>
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <4111d529-3bff-4ce8-abfa-6dcaec7c9e1bn@googlegroups.com>
Subject: Re: DECNet support dropped from Linux kernel
From: jake.ha...@gmail.com (Jake Hamby (Solid State Jake))
Injection-Date: Wed, 08 Nov 2023 19:01:47 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
X-Received-Bytes: 4424
 by: Jake Hamby (Solid St - Wed, 8 Nov 2023 19:01 UTC

On Wednesday, November 8, 2023 at 8:29:37 AM UTC-8, Dave McGuire wrote:
> On 10/6/23 12:18, Scott Dorsey wrote:
> > Just looking at this week's list of kernel updates and noticed this very
> > interesting item tucked in there:
> >
> > Davide Ornaghi discovered that the DECnet network protocol implementation
> > in the Linux kernel contained a null pointer dereference vulnerability. A
> > remote attacker could use this to cause a denial of service (system crash)
> > or possibly execute arbitrary code. Please note that kernel support for the
> > DECnet has been removed to resolve this CVE. (CVE-2023-3338)
> >
> > I can't tell if this is a good or a bad thing.
> It was, of course, a bad thing.
>
> But the problem has been addressed. John Forecast has released his
> DECnet for Linux stack, based on the original, with a great many fixes,
> and many changes to reduce its dependency on moving-target kernel APIs.
>
> https://github.com/JohnForecast/LinuxDECnet
>
> We're testing it here, and so far it works well, and not on ancient
> Linux. We're testing it with Ubuntu 22.04 in a VM under SmartOS.
>
> -Dave
>
> --
> Dave McGuire, President/Curator
> Large Scale Systems Museum
> New Kensington, PA

So you're saying that DECnet belongs in a (computer) museum? That sounds about right. :)

Coincidentally, I was thinking this morning about how I have no interest in setting up either version of DECnet on my x86-64 VMS VM, and wondering how many VMS shops are still using it, and how increasingly difficult it must be for them to route those non-TCP/IP packets. I was also thinking about the exploitable bugs that Simon had posted about discovering, at least in Phase IV, and concerned about how many of those must be still lurking in the code.

I went through a DECnet and VMScluster phase about 10 years ago, when I had two VAXstations and two Alphas, but hadn't bought the Itanium rx2620 blades yet. If I were interested in old versions of VAX/VMS or any of the pre-VAX Digital OS's, it'd still be useful for that. I do know, thanks to YouTuber moshix, that there's a hobbyist global DECnet network called HECnet, along with a hobbyist version of BITNET called HNET.

BITNET/HNET uses IBM's Network Job Entry (NJE) protocol, and HNET has some emulated VAX/VMS systems on it as well as the MVS 3.8j OS that everyone emulates in Hercules because it's the last version that isn't copyright restricted. There's an old commercial app called JNET that allows VAX/VMS to talk to mainframes via TCPNJE. I found a blog post on setting it all up, "VAX/VMS 4.7 with DECnet link to HECnet and IBM Mainframe TCPNJE link to HNET using JNET":

https://supratim-sanyal.blogspot.com/2020/04/vaxvms-47-with-decnet-link-to-hecnet.html

"30-Oct-2023 Update: There is a VMS 4.7 Turnkey Distribution now available for a while from our Discord group. It includes everything and is available here."

"As a working example, JNET version 3.5 works on old VAX/VMS 4.7 operating system."

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor