x

Project Files: Episode 70 — Rooftop Replacement at Texas Motor Speedway

The speedway’s original HVAC equipment, installed nearly 30 years ago, was outdated, and with one HVAC unit per suite, the cost to run and maintain the equipment was significant.




x

New Mexico Opens Home Energy Rebates Program

New Mexico is jump-starting its rebates program by offering low-income owners of single-family homes up to $1,600 off of home insulation purchased at participating retailers. Later, the state will offer rebates for heat pumps and other high-efficiency appliances.




x

Zonex Launches New BACnet Product for its Gen X System

At the core of the BACnetIP solution is the QuickServer gateway, developed by a third-party integrator. This BTL (BACnet Testing Laboratories) certified gateway serves as a communications bridge between the Gen X System and a customer’s building management system.




x

Carbon Monoxide Detectors Serve Multiple Purposes

According to the Centers for Disease Control (CDC), accidental CO poisoning is the cause of approximately 50,000 emergency room visits and more than 400 deaths each year in the U.S.




x

Sporlan Offers Simplified, Safe Products for Less Experienced Techs

The giant clock on top of the Parker Hannifin Corp. — Sporlan Division’s ZoomLock® Roadshow truck counted down during the 2019 AHR Expo, keeping track of the time left until the next live demo. Every 40 minutes, Sporlan would bring attendees up to physically make the connection themselves.




x

Cool Refrigeration Innovations On Display At AHR Expo

At the AHR Expo, manufacturers displayed their latest commercial refrigeration equipment, which included condensing units, components, controls, and other solutions.




x

LG Debuts Chiller, DOAS at AHR Expo

Heat pumps are seen as a main weapon in the battle to stem climate change. LG Electronics specializes in heat pumps, so this was a good opportunity for the company to promote its wares.




x

WaterFurnace Expands Commercial Offerings

At this year’s AHR Expo, WaterFurnace’s booth displayed a branding system that conveys the company leadership’s commitment to the commercial market.




x

ABCs of Externally Equalized TXVs

The TXV also simultaneously controls a set amount of evaporator superheat while, under these same conditions, assuming the range and capacity of the valve is not exceeded.




x

Enter to Win a Trip to the Sixth Annual RIDGID Experience 2023

RIDGID will select six winners for a VIP experience at its global headquarters.




x

Smart Thermostats Set for Rapid Expansion

In the past few years, the thermostat has become a cutting edge electronic. This creates new opportunities for HVAC contractors.




x

Lennox Recognized for Corporate Responsibility and Sustainability

Lennox received a 2023 Green Builder Sustainable Product of the Year recognition.




x

2014 AHR Expo: HVAC Commercial Equipment

The NEWS was very busy at the AHR Expo in New York City, visiting as many booths as possible in search of new products. Below is a comprehensive list of all the HVAC commercial equipment we found on the show floor.




x

BasX Solutions Acquires Seasons 4 Clean Room Product Line

BasX Solutions, a manufacturer of custom engineered products including HVAC solutions, announced that it has completed its acquisition of the clean room product line from Seasons 4.




x

EPA Extends Sell-Through Period, Easing Inventory Concerns

The HVACR industry was initially surprised by a date-of-install requirement, mandating installation of certain equipment by January 1, 2025, but EPA extended sell-through period to January 1, 2026.




x

Refrigerant Sell-Through Period Extended

The EPA initially faced backlash from the industry regarding the sell-through mandate for certain HVAC systems. The Agency revised the provision by allowing one additional year, until January 1, 2026.




x

HVAC Equipment Prices Expected to Keep Rising

In recent years, the cost of HVAC equipment has increased significantly, and regulatory changes, such as the phase-down of R-410A, will make the new A2L units even more expensive.




x

President Biden Proposes Rule to Address Excessive Heat in Workplace

In early July, the Biden administration proposed a rule that addresses excessive heat in the workplace, as tens of millions of them were under heat advisories — the nation’s No. 1 weather-related cause of death.




x

VRF Market Expected to Hit $24B by 2022

Sales of VRF systems continue to rise unabated, leading many to predict their shipments will increase by double digits annually for the foreseeable future.




x

The Best of Extra Edition: May 14, 2018

The NEWS’ Extra Edition page is home to hundreds of online-exclusive service and maintenance, technical, and business management articles. Here are some of the best.




x

Extending the Mini-Split Map

Developments in zoning capabilites have brought mini splits into the multiroom realm. And it goes without mention that the march of engineering progress has taken ductless systems on the road, into parts of the country where no mini split has ever gone before.




x

Ducted Mini-Split Air Handlers Offer Flexibility

Most of the rest of the world has relied on ductless mini-split systems for their heating and cooling needs for decades, but that has not been the case in the U.S. That may be changing with the advent of ducted mini-split systems.




x

LG Earns AHRI Performance Award for the Sixth Consecutive Year

Across seven product categories, LG’s HVAC solutions again pass AHRI's comprehensive performance certification program.




x

Troubleshooting Electronic Expansion Valves

The EEV is often used in modern refrigeration systems, but troubleshooting its common failures may be complicated.




x

Expert Advice on Navigating that First A2L Installation

Manufacturers are starting to introduce their A2L systems in the U.S., so contractors and technicians must learn how to service and install this new equipment.




x

A Little TLC Can Extend the Life of Condensing Units

In today's economy, cost-conscious end users want to extend their HVAC equipment lifespan as long as possible. Regular maintenance on condensing units can help maximize their longevity and performance.




x

Temporary Fixes Can Jumpstart a Refrigeration System

Timely refrigeration repairs are crucial to avoid product loss; temporary fixes can sometimes keep systems running until parts arrive.




x

Three Tips for Your Next System Evacuation

Ensuring a vacuum pump system is evacuated and free of air, nitrogen, moisture, and other contaminants is a crucial step to keep the system running optimally.   




x

Geothermal Industry Expects a Boom

The Inflation Reduction Act’s major incentive for the installation of a qualified geothermal system is a 30% federal clean energy credit, which can be used at filing time to offset taxes owed or add to any refund.




x

Maximizing Indoor Air Quality Without Sacrificing Energy Efficiency

The proper application of modern HVAC technologies can help maximize indoor air quality while minimizing losses in operational efficiency.




x

Why Changing Refrigerants May Mean Your Existing Pump Needs Replacing

When changing the refrigerant within your pumping application, it is worth discussing the application with a process specialist.




x

Nationwide 250 hp Boiler Achieves 5 ppm NOx Performance

Equipped with an Oilon LN30 ultra-low NOx burner and Nationwide’s Eagle PLC-based Control System, the 250 hp package boiler achieved average emissions performance of 5 ppm NOx and 0 ppm CO (corrected to 3% O2) during third-party testing.




x

Re: shell wildcard expansion (un)safety

Posted by Eli Schwartz on Nov 10

The earliest version of the Bash Pitfalls guide that includes a warning
about the topic, per the Wayback Machine:

https://web.archive.org/web/20090426020027/https://mywiki.wooledge.org/BashPitfalls#Filenames_with_leading_dashes

Overall, wildcards are just a classic "here is a programming language
footgun, we cannot fix it because the language is backwards compatible
to the 90s and earlier" which amounts to:

people love bash because...




x

Re: shell wildcard expansion (un)safety

Posted by lists on Nov 10

That says nothing about the amusing character # either at the
start of a name or after whitespace.





x

Re: shell wildcard expansion (un)safety

Posted by Fay Stegerman on Nov 10

* Eli Schwartz <eschwartz () gentoo org> [2024-11-10 00:59]:
[...]

[...]

Obviously, shell scripts and wildcards are one of the easiest ways to trip up
here. But the underlying issue is that CLI interfaces mix options and
arguments: the lack of a clean separation between data and code/commands
(another example is e.g. printing unescaped control characters to stdout,
something discussed on this list before, and far too common IME, as I...




x

Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Xen . org security team on Nov 12

Xen Security Advisory CVE-2024-45819 / XSA-464
version 2

libxl leaks data to PVH guests via ACPI tables

UPDATES IN VERSION 2
====================

Public release.

ISSUE DESCRIPTION
=================

PVH guests have their ACPI tables constructed by the toolstack. The
construction involves building the tables in local memory, which are
then copied into guest memory. While actually used...




x

Xen Security Advisory 463 v2 (CVE-2024-45818) - Deadlock in x86 HVM standard VGA handling

Posted by Xen . org security team on Nov 12

Xen Security Advisory CVE-2024-45818 / XSA-463
version 2

Deadlock in x86 HVM standard VGA handling

UPDATES IN VERSION 2
====================

Public release.

ISSUE DESCRIPTION
=================

The hypervisor contains code to accelerate VGA memory accesses for HVM
guests, when the (virtual) VGA is in "standard" mode. Locking involved
there has an unusual discipline, leaving...




x

Re: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Solar Designer on Nov 12

NIST doesn't appear to provide their own CVSS vectors/scores lately.
However, they republish (with attribution) some third-party ones, this
time from CISA-ADP. The CISA-ADP CVSS vector for this vulnerability
specifies that it not only is network-reachable, but also that it has
High impact not only on Availability, but also on Confidentiality and
Integrity. This results in a CVSSv3.1 score of 9.8. Even merely
correcting the vector not to...




x

Re: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Clemens Lang on Nov 12

Hi,

I think the source for the CISA-ADP data is at [1]. For this specific CVE, the relevant file would be [2]. Their readme
has a section at the bottom, where they encourage feedback:

I’m aware of at last one prior case where a similar case of (IMHO) overblown CVSS scores was discussed in an issue on
this particular GitHub project [3].

Somebody seems to already have opened a ticket for this CVE, too: [4]

[1]:...




x

RE: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Joel GUITTET on Nov 12

Hello
First thanks to Alexander for reposting because I was not able to do so!
You're right Clemens, I have myself ask the question on this github
(https://github.com/cisagov/vulnrichment/issues/130), but still no information for the moment.
Joel




x

Re: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Andrew Cooper on Nov 12

Data are leaked into the PVShim guest, but it is the shim Xen
(exclusively) which has access to the ACPI tables.

The guest which has been shim'd can't architecturally access the leaked
data.

~Andrew




x

Re: shell wildcard expansion (un)safety

Posted by Ali Polatel on Nov 12

Thank you. Around six months ago I added a restriction on filenames with
control characters to Sydbox[1] after I had read about a vulnerability
here on this list. I think it was about tar but my memory may not serve
me right. Sydbox is secure by default, so at first this feature was
enabled without any way to turn it off. After a few months of testing
with fellow Exherbo Linux developers, we have noticed some package tests
(nvim was one of them)...




x

Re: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Demi Marie Obenour on Nov 12

Is this unconditional (perhaps because the relevant data gets zeroed out
by the shim), or does it only apply when the PV guest can't extract data
from the shim's memory? For instance, 32-bit PV guests aren't security
supported anymore, but the PV shim isn't supposed to rely on the
security of the shim itself, only of the rest of the system.




x

CVE-2024-52533: Buffer overflow in socks proxy code in glib < 2.82.1

Posted by Alan Coopersmith on Nov 12

Another CVE was issued by Mitre yesterday for another bug listed on
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home

https://gitlab.gnome.org/GNOME/glib/-/issues/3461 reports that:
"set_connect_msg() receives a buffer of size SOCKS4_CONN_MSG_LEN but it writes
up to SOCKS4_CONN_MSG_LEN + 1 bytes to it. This is because SOCKS4_CONN_MSG_LEN
doesn't account for the trailing nul character that set_connect_msg() appends...




x

Connected RTUs Take the Next Step

Often considered to be an affordable, reliable heating and/or cooling system for a variety of commercial buildings, the standard rooftop unit used to come with a basic thermostat that is limited to turning the system on or off. The advent of new controls has changed all of that by allowing rooftops to monitor operation, analyze conditions, and make real-time decisions that can optimize performance.




x

Emerson’s Equipment Evolutions Strengthen HVACR Experience

Emerson continues to evolve its equipment lines in an effort to introduce its technologies to a broader customer base.




x

BrainBox AI in Agreement to Acquire ABB’s Multisite Retail Energy Management System Integrator Business

BrainBox AI intends to integrate ABB’s MSR business and its installed base of 12,000-plus retail locations in its current operations.





x

Luxaire® Unitary Products: Package Equipment

This series of residential package equipment features energy-saving performance as well as cost-effective installation and maintenance.




x

Serviceability, Flexibility Earn Aaon’s WH Series DDA Gold

Aaon’s focus on serviceability and performance helped the WH Series earn gold in The NEWS’ 2017 Dealer Design Awards HVAC Light Commercial Equipment category.