rn

Re: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Solar Designer on Nov 12

NIST doesn't appear to provide their own CVSS vectors/scores lately.
However, they republish (with attribution) some third-party ones, this
time from CISA-ADP. The CISA-ADP CVSS vector for this vulnerability
specifies that it not only is network-reachable, but also that it has
High impact not only on Availability, but also on Confidentiality and
Integrity. This results in a CVSSv3.1 score of 9.8. Even merely
correcting the vector not to...




rn

Re: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Clemens Lang on Nov 12

Hi,

I think the source for the CISA-ADP data is at [1]. For this specific CVE, the relevant file would be [2]. Their readme
has a section at the bottom, where they encourage feedback:

I’m aware of at last one prior case where a similar case of (IMHO) overblown CVSS scores was discussed in an issue on
this particular GitHub project [3].

Somebody seems to already have opened a ticket for this CVE, too: [4]

[1]:...




rn

RE: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Joel GUITTET on Nov 12

Hello
First thanks to Alexander for reposting because I was not able to do so!
You're right Clemens, I have myself ask the question on this github
(https://github.com/cisagov/vulnrichment/issues/130), but still no information for the moment.
Joel




rn

Serviceability, Flexibility Earn Aaon’s WH Series DDA Gold

Aaon’s focus on serviceability and performance helped the WH Series earn gold in The NEWS’ 2017 Dealer Design Awards HVAC Light Commercial Equipment category.




rn

Bluetooth Technology, Battery Strength Earn ManTooth the Gold

The ManTooth™ Wireless Digital Pressure/Temperature Gauge from Yellow Jacket Products Division, Ritchie Engineering Co., is this year's gold winner in the Electronic Tools category.




rn

Internet of Things Advancements Improve HVAC Equipment, Service Technology

The Internet of Things is a broad term with multiple definitions, likely stemming from the different sectors of technology that IoT impacts.




rn

M.C. Dean Acquires International Energy Conservation Systems

IEC Systems is a provider of turnkey proprietary and nonproprietary building automation systems (BASs) and a Distech Controls authorized system integrator.




rn

BAS and Environmental, Social, and Governance Principles

Since more companies are putting a focus on ESG principles, the HVAC industry is positioned to turn those goals, into a reality.




rn

California Musician Pens Love Song to Heat Pumps

“(I’m Your) Heat Pump” is a soft, funky, R&B love song told from the perspective of a heat pump that depicts just what a heat pump can provide to its users.




rn

California Heat Pump Partnership Aims to Scale Up Electrification of HVAC

This new private-public partnership wants to quadruple heat pump installation in California over the next 6 years.




rn

Troubleshooting Puzzle: An Electric Furnace That’s Not Performing

The equipment in this month’s troubleshooting problem is an electric furnace that has been in service for at least ten years and has no service history.




rn

How to Explain Odor from Gas Furnace

Any furnace with induced draft combustion may occasionally exhibit unburned gas odor near the furnace in the off cycle.




rn

Department of Energy May Bump Up Furnace Standards

Two major HVAC industry organizations have weighed in on a DOE proposal that would phase out noncondensing gas furnaces for consumer use beginning in about six years.




rn

Three Ways Contractors Can Make High-End Furnaces ‘Sell Themselves’

If contractors in colder climates focus on educating their customers on what new higher-efficiency furnaces bring to the table, often times the furnaces will sell themselves.




rn

Basic Furnace Maintenance and Troubleshooting

The ACHR NEWS visited Flame Furnace in Warren, Michigan to learn how to do maintenance and basic troubleshooting on a furnace.




rn

Residential Heating Scene Shows Mix of Cold Climate Heat Pumps, Furnaces

Cold climate heat pumps were on full display on the AHR show floor and manufacturers were eager to share their progress reports in the Department of Energy’s CCHP Challenge.




rn

Judge Overturns Berkeley Gas Infrastructure Ban

The decision is a win for the California Restaurant Association, which challenged the ban that took effect in 2020. The city has not decided whether to appeal.




rn

DOE Issues 95% AFUE Rule For New Gas Furnaces

Manufacturers will have five years, from the date the rule is published in the Federal Register, to ensure that new gas furnaces comply with the new minimum.




rn

Mandating High-Efficiency Furnaces Will Limit Consumer Choice, Critics in HVAC Industry Say

Residential gas furnaces must all have a minimum AFUE of 95% beginning in five years. Some in the HVAC industry say the new Department of Energy rule will ultimately hurt homeowners.




rn

Industry Reacts to Gas Furnace Mandate

This winter, HVAC contractors might be dealing with a wetter winter than years past, coupled with more snowfall than maybe most people would like.




rn

Trade Groups File Challenge to DOE Furnace Rule

The final rule from the U.S. Department of Energy, issued recently, requires newly manufactured indoor residential gas furnaces to be at least 95% efficient starting in December 2028, meaning furnaces made after then will have to be condensing models.




rn

How a Condensing Gas Furnace Works

Taking a look at the major concerns around replacing an 80% furnace with a high-efficiency one such as venting requirements, drilling extra holes, and financial costs.




rn

Ted Cruz Gives DOE Furnace Rule Pushback

U.S. Senator Ted Cruz is leading the charge to assist HVAC contractors in pushing back on the final rule on gas furnace efficiency standards from the U.S. Department of Energy (DOE).




rn

Hydronic Furnaces are Changing the Forced Air Heating Game

Using water to transfer heat energy into the home can minimize or even eliminate the issues of dry air and loud operation.




rn

Furnace Red Tag Second Opinions

There are plenty of reasons to shut down a potentially dangerous furnace, just make sure the facts back up that decision. 




rn

Effectively Navigating Red Tag Second Opinions on Furnaces

If contractors don’t have a plan in place to handle red tag furnace second opinions, they can expect some mistakes.




rn

Improving Home Comfort and Energy Efficiency with the Navien NPF Series Hydro-furnace

A homeowner in Pickering, Ontario works with an experienced HVAC pro to improve comfort, efficiency, and energy savings with a high-efficiency hydronic forced-air furnace upgrade.




rn

Episode 1: Patterns

In this episode Michael and Markus talk about patterns. Starting with some of their "most used" patterns, they go into some detail about the history of patterns. They then discuss the various pattern forms as well as some misconceptions about patterns. Other topics include the domains that are covered by patterns as well as pattern languages.




rn

Episode 40: Interview Werner Vogels

This episode is an interview with Werner Vogels, the CTO of amazon.com. We first talked about what scalability is, and which aspects there are to scalability. We then took a brief look at the technologies used at amazon, specifically, the middleware systems and the issue of vendor lock-in. Web services, and the role of SOA was the next topic. Then we covered what a service actually is add Werner explained the term "pizza teams". Testing and Deployment was the next topic followed by a look at architectural characteristics of scalable systems, the value of simplicity and the CAP theorem. We concluded the discussion with a brief look at the future of distributed systems




rn

Episode 41: Architecture Patterns (Architecture Pt. 4)

This is the fourth and final episode on the fundamentals of Software Architecture. We talk mainly about architectural styles and patterns, as introduced in the POSA 1 Book. We also discuss a little bit the process of actually using those patterns for architecting systems.




rn

Episode 61: Internals of GCC

This show takes a behind-the-scenes look at compilers and their inner workings, using the Gnu compiler collection (GCC) as an example. Arno interview Morgan Deters, covering all steps from the parsing of different programming languages to machine independenet optimizations and generating processor specific binary code.




rn

Episode 63: A Pattern Language for Distributed Systems with Henney and Buschmann

In this Episode we talked about the new POSA 4 book which has recently been published. We talk to two of the authors, Kevlin Henney and Frank Buschmann (the third author, Doug Schmidt was not available - and he had also been on the podcast a couple of times :-)). The book contains a pattern language for distributed systems. It contains 114 patterns that had been published before by many different other authors. The patterns have been rewritten to form a consistent language. We basically talked through the different sections of the book, which gives a really good overview over the challenges and the solutions of building distributed systems. These sections include From Mud to Structure, Distribution Infrastructure, Event Demultiplexing and Dispatching, Interface Partitioning, Component Patitioning, Application Contrl, Concurrency, Synchronization, Object Interaction, Adaptazion and Extension, Modal Behaviour, Resource Management and finally, Database Access. The book references several other previous works (as listed below). Interestingly, many of these referenced works and authors have also been discussed previously on the podcast. Here are the back references:




rn

Episode 70: Gerard Meszaros on XUnit Test Patterns

In this episode we talk with Gerard Meszaros about problems and challenges doing unit testing in real-world projects. Starting from a short discussion about the importance of automated unit testing we spend most of this episode to talk about every day problems doing unit testing and how those problems can be solved. Based on this book on xunit testing patterns, Gerard talks about his experiences with unit test smells as an analogy to code smells. He describes an impressive set of unit testing patterns to overcome those difficult testing situations and illustrates them with nice examples everybody doing unit testing will feel familiar with.




rn

Episode 76: Special Episode on the Patterns Journal

In this special Episode we briefly discuss the upcoming Patterns Journal with the two editors, Ralph Johnson and James Noble.




rn

Episode 93: Lessons Learned From Architecture Reviews with Rebecca Wirfs-Brock

In this episode, Markus talks to Rebecca Wirfs-Brock on what she has learned from architecture reviews. This is a very complement to the earlier episode on architecture evaluation.




rn

Episode 95: The New Guardian.co.uk website with Matt Wall and Erik DoernenBurg

In this episode we talk to Matthew Wall (Guardian News and Media) and Erik Doernenburg (Thoughtworks) about their work on the new guardian.co.uk website. We discuss the challenge of scalability and interactivity, their use of Domain Driven Design, some of the technical building blocks as well as the approaches they use for performance measuring and scalability tuning.




rn

Episode 96: Interview Krzysztof Czarnecki

This episode is the long-awaited (and much requested) interview with Krzysztof Czarnecki, the author, together with Ulrich Eisenecker, of the book Generative Programming. In the interview we discussed the state of generative programming today and related it to model-driven development and DSLs. We then talked a little bit about product lines in general. We then discussed his current field of research, which currently focusses on framework-specific modeling languages and non-trivial roundtrip engineering.




rn

Episode 138: Learning as a Part of Development with Allan Kelly

In this episode, Allan shares his insights about how learning is a necessary part of software development. He covers the personal as well as the team and the organizational level and offers practical advice.




rn

Episode 146: Interesting Patterns at EuroPLoP 2009

This episode is a discussion with various authors of patterns reviewed at EuroPLoP 2009. Topics include Product Line Engineering, Distributed Development, Open Source and Embedded Systems




rn

Episode 216: Adrian Cockcroft on the Modern Cloud-based Platform

Adrian Cockcroft discusses the challenges in creating a dynamic, flexible, cloud-based platform with SE Radio host Stefan Tilkov. After briefly discussing the definition of “cloud computing,” Adrian explains the history behind Netflix’s move to the cloud (which he led). After highlighting some of the differences that have developers and architects must face, Adrian talks about […]




rn

Episode 217: James Turnbull on Docker

James Turnbull joins Charles Anderson to discuss Docker, an open source platform for distributed applications for developers and system administrators. Topics include Linux containers and the functions they provide, container images and how they are built, use cases for containers, and the future of containers versus virtual machines. Venue: Internet Related Links James’s home page: […]




rn

SE-Radio Episode 239: Andrew Clay Shafer on Modern Platform-as-a-Service




rn

SE Radio Episode 244: Gernot Starke on Architecture Documentation using arc42

Gernot Starke talks about arc42: an open-source set of templates he developed to document software architecture based on his practical experience with real projects. Also Gernot and host Eberhard then discuss how documenting architecture fits into agile processes and how to find the right amount of documentation for a system. They walk through the different parts of the arc42 templates covering requirements and the context of the system and the solution structure, including building blocks, runtime, and deployment. They discuss tooling, versioning, testing documentation, and how to keep documentation up to date.




rn

SE-Radio-Show-246:-John-Wilkes-on-Borg-and-Kubernetes

John Wilkes from Google talks with Charles Anderson about managing large clusters of machines. The discussion starts with Borg, Google’s internal cluster management program. John discusses what Borg does and what it provides to programmers and system administrators. He also describes Kubernetes, an open-source cluster management system recently developed by Google using lessons learned from Borg, Mesos, and Omega




rn

SE-Radio-Episode-249:-Vaughn-Vernon-on-Reactive-Programming-with-the-Actor-Model




rn

Camille Fournier on Real-World Distributed Systems

Stefan Tilkov talks to Camille Fournier about the challenges developers face when building distributed systems, whether the can avoid building them at all, and what changes occur once they do.




rn

SE-Radio Episode 271: Idit Levine on Unikernelsl

Jeff Meyerson talks to Idit Levine about Unikernels and unik, a project for compiling unikernels. The Linux kernel contains features that may be unnecessary to many application developers--particularly if those developers are deploying to the cloud. Unikernels allow programmers to specify the minimum features of an operating system we need to deploy our applications. Topics include the the Linux kernel, requirements for a cloud operating system, and how unikernels compare to Docker containers.




rn

SE-Radio-Episode-276-Björn-Rabenstein-on-Site-Reliability-Engineering

Björn Rabenstein discusses the field of Site Reliability Engineering (SRE) with host Robert Blumen. The term SRE has recently emerged to mean Google's approach to DevOps. The publication of Google's book on SRE has brought many of their practices into more public discussion. The interview covers: what is distinct about SRE versus devops; the SRE focus on development of operational software to minimize manual tasks; the emphasis on reliability; Dickerson's hierarchy of reliability; how reliability can be measured; is there such a thing as too much reliability?; can Google's approach to SRE be applied outside of Google?; Björn's experience in applying SRE to Soundcloud - what worked and what did not; how can engineers best apply SRE to their organizational situation?; the importance of monitoring; monitoring and alerting; being on call, responding to incidents; the importance of documentation for responding to problems; they wrap up with a discussion of why people from non-computer science backgrounds are often found in devops and SRE.




rn

SE-Radio Episode 284: John Allspaw on System Failures: Preventing, Responding, and Learning From

John Allspaw CTO of Etsy speaks with Robert Blumen about systemic failures and outages. Why they cannot be totally prevented, how to respond, and what we can learn from them.




rn

SE-Radio-Episode-286-Katie-Malone-Intro-to-Machine-Learning

Show host Edaena Salinas talks with Katie Malone about Machine Learning.  Katie Malone is a Data Scientist in the Research and Development department at Civis Analytics. She is also an instructor of the Intro to Machine Learning online course from Udacity and host of Linear Digressions, a podcast about machine learning. Topics include: machine learning, data science, a career in machine learning.