From patchwork Fri Jul 3 14:52:50 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Florian Weimer X-Patchwork-Id: 138442 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id E31774BA23C5 for ; Fri, 3 Jul 2026 15:00:47 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org E31774BA23C5 Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=dbDhOdQj X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by sourceware.org (Postfix) with ESMTP id 3112F4BA2E1D for ; Fri, 3 Jul 2026 14:52:56 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 3112F4BA2E1D Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 3112F4BA2E1D Authentication-Results: sourceware.org; arc=none smtp.remote-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090376; cv=none; b=HWj25Q1c4RL8BvYENOMqy/vkPsmYn0tdiUj8X1+eA4WEczUxTdkU6MK5OfA5mpekLcVApovL5ODDKvcbvrrgmEVBCDlaQ3ZXNWVHsUerYBrpu5Ot1b3nWL/C6vTwVR0tyL4tDPsC2k6HbnzRitF76SZ1gq4iv0iQbtZEMMpa2rk= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090376; c=relaxed/simple; bh=S4xd/tktL+IVUsPBTHnhWGhiRQWAz5Bwot68v4fx3mM=; h=DKIM-Signature:From:To:Subject:Message-ID:Date:MIME-Version; b=GTmTv5k7/gbbyyAHpLtOtezc8/SMAx35rTG6taUNdpBCFS5ubJb85fCRl4Iu+s6XVkMroB9A29JZCxh93toJXvlWmJHMDpXhqVsOH272igN4spI5SplAtmki2EWxqc67CoddyTKUYl2lgFbtTmqqht13EGVZWLrSCqzfjqFBnAM= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=dbDhOdQj DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 3112F4BA2E1D DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783090375; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=juNkapGOnbAseFjrYJbD1ixQEyUGXpCVgfIrgxp08d4=; b=dbDhOdQj/F/5FHyp6bu/k4G4ZR1SMA7N2ifxe9j4gKsIwTUBcKabgk7EzhzlF7+9K2Iwu9 +P2WlqWNe2wDsEwp9NaiT9Kr+srLKFKFqSsT/DNaSj320fNBgPL6GrMn37FcQCzjtHQ2wR ge/kQZS9NfC62FoxeOY1FSagiPAbAZQ= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-549-izoLEuGjPiqQMRd71XkJaQ-1; Fri, 03 Jul 2026 10:52:54 -0400 X-MC-Unique: izoLEuGjPiqQMRd71XkJaQ-1 X-Mimecast-MFC-AGG-ID: izoLEuGjPiqQMRd71XkJaQ_1783090373 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6E8E918CC48E for ; Fri, 3 Jul 2026 14:52:53 +0000 (UTC) Received: from oldenburg3.str.redhat.com (unknown [10.44.50.50]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id BB2F236F04 for ; Fri, 3 Jul 2026 14:52:52 +0000 (UTC) From: Florian Weimer To: libc-alpha@sourceware.org Subject: [PATCH 1/4] support: Add resolv_response_set_buffer In-Reply-To: Message-ID: References: X-From-Line: da99017797e4be1e2d6516e2430e97d55558e5f5 Mon Sep 17 00:00:00 2001 Date: Fri, 03 Jul 2026 16:52:50 +0200 User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: VLZhTQUc7Z_IZAfHnGOnFQRpEZHj0wL5Cob7S8C9otA_1783090373 X-Mimecast-Originator: redhat.com X-Spam-Status: No, score=-10.9 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, SPF_HELO_PASS, SPF_NONE, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org This can be used to mangle the response data to exercise the DNS client with corrupted packets. Also change resolv_response_buffer not to allocate. Instead, just return a pointer to the internal buffer. The function is currently unused. Reviewed-by: Adhemerval Zanella --- support/resolv_test.c | 17 +++++++++++++---- support/resolv_test.h | 15 +++++++++++++++ 2 files changed, 28 insertions(+), 4 deletions(-) diff --git a/support/resolv_test.c b/support/resolv_test.c index ec406b281a..4bb642f439 100644 --- a/support/resolv_test.c +++ b/support/resolv_test.c @@ -429,11 +429,20 @@ resolv_response_length (const struct resolv_response_builder *b) } unsigned char * -resolv_response_buffer (const struct resolv_response_builder *b) +resolv_response_buffer (struct resolv_response_builder *b) { - unsigned char *result = xmalloc (b->offset); - memcpy (result, b->buffer, b->offset); - return result; + return b->buffer; +} + +void +resolv_response_set_buffer (struct resolv_response_builder *b, + const unsigned char *data, size_t length) +{ + if (length > max_response_length) + FAIL_EXIT1 ("resolv_response_set_buffer: length %zu exceeds maximum %d", + length, max_response_length); + memmove (b->buffer, data, length); + b->offset = length; } struct resolv_response_builder * diff --git a/support/resolv_test.h b/support/resolv_test.h index 7a81c1c513..c10c523eb4 100644 --- a/support/resolv_test.h +++ b/support/resolv_test.h @@ -206,6 +206,21 @@ void resolv_response_close (struct resolv_response_builder *); /* The size of the response packet built so far. */ size_t resolv_response_length (const struct resolv_response_builder *); +/* Return a pointer to the internal response buffer. The pointer is + only valid until the next call that modifies the builder. The + length of the byte array can be obtained using + resolv_response_length. */ +unsigned char *resolv_response_buffer (struct resolv_response_builder *) + __attribute_nonnull__ ((1)); + +/* Replace the contents of the response buffer contents with a copy of + LENGTH bytes starting at DATA. Passing the pointer returned by + resolv_response_buffer is valid. If LENGTH is larger than the + maximum support packet size, fail the process. */ +void resolv_response_set_buffer (struct resolv_response_builder *, + const unsigned char *data, size_t length) + __attribute_nonnull__ ((1, 2)); + /* Allocates a response builder tied to a specific query packet, starting at QUERY_BUFFER, containing QUERY_LENGTH bytes. */ struct resolv_response_builder * From patchwork Fri Jul 3 14:52:55 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Florian Weimer X-Patchwork-Id: 138437 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 38EF14BA23F8 for ; Fri, 3 Jul 2026 14:57:09 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 38EF14BA23F8 Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=WAbVQari X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by sourceware.org (Postfix) with ESMTP id AF8114BA23D3 for ; Fri, 3 Jul 2026 14:53:01 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org AF8114BA23D3 Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org AF8114BA23D3 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090381; cv=none; b=MC6T2Vv+jsg1GWtuNsptAHoYtAJDai3W1VzeTdTPTlwjpERxA4rp53YL6DsV3t2zR4uhZpwxsUVC3Kaqsh12WViXnxxRl4VzpqQGzSil5ESG+OmuWV2Z4Te2br6G7DHCvZtP3/TlTEEXjGx2ov5OL7BAc/qH+Czm+mvIQ1pkv9w= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090381; c=relaxed/simple; bh=RC9bAP6oAsgVSnZ7RaqvexJ0a6maodBCyl4A+F/n4KY=; h=DKIM-Signature:From:To:Subject:Message-ID:Date:MIME-Version; b=LNZZ7hMbpm1JJtn6uGuQt9lZN4R/hFyA/x9E3kxoUuUzIgUitWYILldBe0lLaS0eqfO90c+tbFTrT6fS5aRp+iiGjnl3p6eZels9ahN6a9s2ZADe6xDFSLChNifpu2OtG0c7siAM2rKO4nSA8rStyCfZk4dRGEB3NVRV0SzzneE= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=WAbVQari DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org AF8114BA23D3 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783090381; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=gilonC3cmJw940cnlEWxXAQIvqTdC4DCXjUiW1p7kMM=; b=WAbVQariZi2yHMej+l2J8u6k9Zjs17NhV8xrfSpVNQpBf+kOYymO9xAhBwYLcDpuxijW8e Lt5wsS9/1Xdpg5vqWAoFJYAObRCyAjChUgaSAZIGRt8h8jTcZGpVt9WeqNf1mNsMRX/jQX euOKtgfgcTGkip4aw9gh9NcVF+F7MiA= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-462-LG56lwUNOA-j1XE42B4Mxw-1; Fri, 03 Jul 2026 10:53:00 -0400 X-MC-Unique: LG56lwUNOA-j1XE42B4Mxw-1 X-Mimecast-MFC-AGG-ID: LG56lwUNOA-j1XE42B4Mxw_1783090379 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 6BFB41863B25 for ; Fri, 3 Jul 2026 14:52:59 +0000 (UTC) Received: from oldenburg3.str.redhat.com (unknown [10.44.50.50]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id B810E36F2C for ; Fri, 3 Jul 2026 14:52:58 +0000 (UTC) From: Florian Weimer To: libc-alpha@sourceware.org Subject: [PATCH 2/4] resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345) In-Reply-To: Message-ID: References: X-From-Line: f2a05fdecf84b81dbb13d1b05c991b2aff8e1c86 Mon Sep 17 00:00:00 2001 Date: Fri, 03 Jul 2026 16:52:55 +0200 User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: kJrZvMqLr9sgUJC_jfpQ9whzg2jj6du0AGmpzcvotYI_1783090379 X-Mimecast-Originator: redhat.com X-Spam-Status: No, score=-10.9 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H4, RCVD_IN_MSPIKE_WL, SPF_HELO_PASS, SPF_NONE, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org The __libc_res_nameinquery function returns -1 for corrupted packets. The previous code treated those as matching. This is not a security vulnerability because the transaction ID is still checked. The bug does not make off-path attacks substantially easier. Furthermore, most users of the DNS stub resolver parse the question name again, and do not simply skip over it using dn_skipname or similar (which would hide the corruption). This means that the packet is still rejected at a later stage. Reviewed-by: Adhemerval Zanella --- resolv/res_queriesmatch.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/resolv/res_queriesmatch.c b/resolv/res_queriesmatch.c index 08d82f1814..a11d0b4fc7 100644 --- a/resolv/res_queriesmatch.c +++ b/resolv/res_queriesmatch.c @@ -122,7 +122,8 @@ __libc_res_queriesmatch (const unsigned char *buf1, const unsigned char *eom1, return -1; NS_GET16 (ttype, cp); NS_GET16 (tclass, cp); - if (!__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2)) + if (__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2) <= 0) + /* Parse error or mismatch. */ return 0; } return 1; From patchwork Fri Jul 3 14:53:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Florian Weimer X-Patchwork-Id: 138441 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 22B754BA23DB for ; Fri, 3 Jul 2026 14:59:16 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 22B754BA23DB Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=ZvCR37mP X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) by sourceware.org (Postfix) with ESMTP id 443FE4BA23DB for ; Fri, 3 Jul 2026 14:53:08 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 443FE4BA23DB Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 443FE4BA23DB Authentication-Results: sourceware.org; arc=none smtp.remote-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090388; cv=none; b=oAPF0eWcBDmd9rruMqCHpumKQjIXgRMQKsbaBXEyY3hg5YgH3EvvEa14/7jN4NAXPewL5XAzSlASx2wrmf46GTiajZWL+DBiDVb8+7/VwoYjlZWq/CM6LhdCuHyOJ228iN/oEKOpUMk9kFhrunopzAJz+0OtpVViXDvExANlM+8= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090388; c=relaxed/simple; bh=/WQv/nSPPhF2pfCYBtNPrN8jOzh337OZcGxFkCQGRHQ=; h=DKIM-Signature:From:To:Subject:Message-ID:Date:MIME-Version; b=OQ+Aq1D5Z+jEyEFnc3YqovWKtLtBkSfJ6wMr1L4DHNV5N0fU4JwwGISJ2FXMxXUPATDkCcLPJ8yMsczARWOULNeDLxF5iR13VHpyF62zrTI2CubwVvQ/CgQFvW1ik5Y7cNFDYTnZ00r8+iwXVadXzwnJd07Jg0Zy0FmgFHCxRos= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=ZvCR37mP DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 443FE4BA23DB DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783090387; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=DJ+dTDT+I1/wzW371NFeF7J1P9Zgtr9EeJW4yH4v55Q=; b=ZvCR37mPhW1PmL/97v/DGh33J7ggt2fGYx+sK4jb4T5e46yYftlU7ZScMoidmypL7qlivh O0FVcZPlmMo1X6xAX+Mb25xgZmVHZdnWO1JCaYhOHxVTUWhDFR58ZrCKI3o8VwVKVd96cG QK8gxKqV2qj36KpmurCv5GypoPb8rG0= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-384-xF3iBjH2PDCGvlvlNrooyA-1; Fri, 03 Jul 2026 10:53:06 -0400 X-MC-Unique: xF3iBjH2PDCGvlvlNrooyA-1 X-Mimecast-MFC-AGG-ID: xF3iBjH2PDCGvlvlNrooyA_1783090386 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id DA28D1935DEE for ; Fri, 3 Jul 2026 14:53:05 +0000 (UTC) Received: from oldenburg3.str.redhat.com (unknown [10.44.50.50]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 30D9F1800613 for ; Fri, 3 Jul 2026 14:53:04 +0000 (UTC) From: Florian Weimer To: libc-alpha@sourceware.org Subject: [PATCH 3/4] resolv: Fix __libc_res_queriesmatch buffer size argument in send_dg (bug 34346) In-Reply-To: Message-ID: <99ad4d202644810ba322af9edec713f60f23fb3e.1783089265.git.fweimer@redhat.com> References: X-From-Line: 99ad4d202644810ba322af9edec713f60f23fb3e Mon Sep 17 00:00:00 2001 Date: Fri, 03 Jul 2026 16:53:02 +0200 User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: tz5cfYMHaQleSwz-gfFczfq1HDfFvKsnKlEAMrmKv68_1783090386 X-Mimecast-Originator: redhat.com X-Spam-Status: No, score=-9.5 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H4, RCVD_IN_MSPIKE_WL, RCVD_IN_SBL_CSS, SPF_HELO_PASS, SPF_NONE, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org Pass the number of bytes written by recvfrom, not the entire size of the buffer. This is not a security vulnerability because it only allows confirmation of previously existing buffer values. All reads stay within the specified buffer bounds. The buffer contents may not have been initialized. Subsequent processing is correctly capped at buffer bounds, too. Reviewed-by: Adhemerval Zanella --- resolv/res_send.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/resolv/res_send.c b/resolv/res_send.c index cf27fa7ad6..cc65a03e7d 100644 --- a/resolv/res_send.c +++ b/resolv/res_send.c @@ -1215,14 +1215,14 @@ send_dg(res_state statp, && (skip_query_match || __libc_res_queriesmatch (buf, buf + buflen, *thisansp, - *thisansp + *thisanssizp))) + *thisansp + *thisresplenp))) matching_query = 1; if (!recvresp2 && anhp->id == hp2->id && (skip_query_match || __libc_res_queriesmatch (buf2, buf2 + buflen2, *thisansp, - *thisansp + *thisanssizp))) + *thisansp + *thisresplenp))) matching_query = 2; if (matching_query == 0) /* Spurious UDP packet. Drop it and continue From patchwork Fri Jul 3 14:53:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Florian Weimer X-Patchwork-Id: 138440 Return-Path: X-Original-To: patchwork@sourceware.org Delivered-To: patchwork@sourceware.org Received: from vm01.sourceware.org (localhost [IPv6:::1]) by sourceware.org (Postfix) with ESMTP id 03B4E4BA23FF for ; Fri, 3 Jul 2026 14:58:36 +0000 (GMT) DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 03B4E4BA23FF Authentication-Results: sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=T4zQd7kc X-Original-To: libc-alpha@sourceware.org Delivered-To: libc-alpha@sourceware.org Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by sourceware.org (Postfix) with ESMTP id 5E6884BA7982 for ; Fri, 3 Jul 2026 14:53:13 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 5E6884BA7982 Authentication-Results: sourceware.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=redhat.com ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 5E6884BA7982 Authentication-Results: sourceware.org; arc=none smtp.remote-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090393; cv=none; b=Qd8S6Ov1/0EqxGuBvC1yrsW4t6naESMwN5TF+mWfxoP5i4afOkI7uaUDg4Tm/c+M20AP6ZWXdi/POBlmjfioC1p1F9SZtIQYKhza0CRgN9dKXg5qFqhlh0FFhsaHY40n1JsH2vnsA7tLyMYI2Ewy/xHfWPliEyTwUiEOL8YQERw= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1783090393; c=relaxed/simple; bh=3jfxJnwQH0QWkYhKEsm8/FRUifJcXanAMus7vED7sgU=; h=DKIM-Signature:From:To:Subject:Message-ID:Date:MIME-Version; b=vR9pCv83F9J2Vdm+RaJTrnPHN1x8edR+HqntDlEk5Nx41LsqgqXumzD7MEk+clO5RU3f2VJMhawLaKDfU5PCiQdm0mJkRw6VsYYXRvOPUTkdabppac/R1eRV6PQDSDZg8LdhvGyFeh1ZIOWZI5Z/jdBwJ/Asc2dctNeYtlqeArk= ARC-Authentication-Results: i=1; sourceware.org; dkim=pass (1024-bit key, unprotected) header.d=redhat.com header.i=@redhat.com header.a=rsa-sha256 header.s=mimecast20190719 header.b=T4zQd7kc DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 5E6884BA7982 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783090393; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: in-reply-to:in-reply-to:references:references; bh=d1xSeXlHWirzw3h9Z+QUZeWcwAfE4h87m/nUjl4IOtc=; b=T4zQd7kcWb277ABMkcCntwTYmjC9vUnbU5lVHV9m1aAGL6oZx68XbkISy7s9r0Tq3gGovv Vqu9ajVeUqdoSxYe1eSvGFsdr/puDy2n9bUVN79/VcD5Gvx0Ghoj8ScauiL1vQvHO50twu 3/LQISzcTSM7bfnb/IYHPvh9eAmqoWw= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-423-ksciYN9YMTyssB2_M_ubcw-1; Fri, 03 Jul 2026 10:53:11 -0400 X-MC-Unique: ksciYN9YMTyssB2_M_ubcw-1 X-Mimecast-MFC-AGG-ID: ksciYN9YMTyssB2_M_ubcw_1783090391 Received: from mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id E7BAE196CDCC for ; Fri, 3 Jul 2026 14:53:10 +0000 (UTC) Received: from oldenburg3.str.redhat.com (unknown [10.44.50.50]) by mx-prod-int-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 3DDFE1971E7A for ; Fri, 3 Jul 2026 14:53:10 +0000 (UTC) From: Florian Weimer To: libc-alpha@sourceware.org Subject: [PATCH 4/4] resolv: Test case for accepting mismatching, corrupted packets In-Reply-To: Message-ID: <14102cf01f9390924a38d39d691c7a6b672f2b2c.1783089265.git.fweimer@redhat.com> References: X-From-Line: 14102cf01f9390924a38d39d691c7a6b672f2b2c Mon Sep 17 00:00:00 2001 Date: Fri, 03 Jul 2026 16:53:07 +0200 User-Agent: Gnus/5.13 (Gnus v5.13) MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.0 on 10.30.177.17 X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: fhJES1UZaQmQfrP2JIAdMU9rDfEmTnmnUMQ0vopPLC4_1783090391 X-Mimecast-Originator: redhat.com X-Spam-Status: No, score=-9.5 required=5.0 tests=BAYES_00, DKIMWL_WL_HIGH, DKIM_SIGNED, DKIM_VALID, DKIM_VALID_AU, DKIM_VALID_EF, GIT_PATCH_0, KAM_SHORT, RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3, RCVD_IN_MSPIKE_WL, RCVD_IN_SBL_CSS, SPF_HELO_PASS, SPF_NONE, TXREP shortcircuit=no autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org X-BeenThere: libc-alpha@sourceware.org X-Mailman-Version: 2.1.30 Precedence: list List-Id: Libc-alpha mailing list List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: libc-alpha-bounces~patchwork=sourceware.org@sourceware.org The test skeleton was auto-generated. I think this is fine because the harness is so specific to glibc. Assisted-by: LLM Reviewed-by: Adhemerval Zanella --- resolv/Makefile | 3 + resolv/tst-resolv-querymatch-short.c | 109 +++++++++++++++++++++++++++ 2 files changed, 112 insertions(+) create mode 100644 resolv/tst-resolv-querymatch-short.c diff --git a/resolv/Makefile b/resolv/Makefile index 28f6ba6c3b..e53a2b9bce 100644 --- a/resolv/Makefile +++ b/resolv/Makefile @@ -123,6 +123,7 @@ tests += \ tst-resolv-noaaaa \ tst-resolv-noaaaa-vc \ tst-resolv-nondecimal \ + tst-resolv-querymatch-short \ tst-resolv-res_init-failure \ tst-resolv-res_init-multi \ tst-resolv-search \ @@ -326,6 +327,8 @@ $(objpfx)tst-resolv-no-search: $(objpfx)libresolv.so $(shared-thread-library) $(objpfx)tst-resolv-noaaaa: $(objpfx)libresolv.so $(shared-thread-library) $(objpfx)tst-resolv-noaaaa-vc: $(objpfx)libresolv.so $(shared-thread-library) $(objpfx)tst-resolv-nondecimal: $(objpfx)libresolv.so $(shared-thread-library) +$(objpfx)tst-resolv-querymatch-short: $(objpfx)libresolv.so \ + $(shared-thread-library) $(objpfx)tst-resolv-qtypes: $(objpfx)libresolv.so $(shared-thread-library) $(objpfx)tst-resolv-rotate: $(objpfx)libresolv.so $(shared-thread-library) $(objpfx)tst-resolv-search: $(objpfx)libresolv.so $(shared-thread-library) diff --git a/resolv/tst-resolv-querymatch-short.c b/resolv/tst-resolv-querymatch-short.c new file mode 100644 index 0000000000..d9f9409622 --- /dev/null +++ b/resolv/tst-resolv-querymatch-short.c @@ -0,0 +1,109 @@ +/* Test res_queriesmatch buffer handling (bug 34345, bug 34346). + Copyright (C) 2026 Free Software Foundation, Inc. + This file is part of the GNU C Library. + + The GNU C Library is free software; you can redistribute it and/or + modify it under the terms of the GNU Lesser General Public + License as published by the Free Software Foundation; either + version 2.1 of the License, or (at your option) any later version. + + The GNU C Library is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU + Lesser General Public License for more details. + + You should have received a copy of the GNU Lesser General Public + License along with the GNU C Library; if not, see + . */ + +#include +#include +#include +#include +#include + +static void +response (const struct resolv_response_context *ctx, + struct resolv_response_builder *b, + const char *qname, uint16_t qclass, uint16_t qtype) +{ + switch (ctx->server_index) + { + case 0: + { + struct resolv_response_flags flags = { .rcode = 3 }; /* NXDOMAIN. */ + resolv_response_init (b, flags); + resolv_response_add_question (b, qname, qclass, qtype); + + /* Cause a mismatch in the transaction ID. */ + *resolv_response_buffer (b) ^= 1; + } + break; + + case 1: + { + struct resolv_response_flags flags = { .rcode = 3 }; /* NXDOMAIN. */ + resolv_response_init (b, flags); + resolv_response_add_question (b, qname, qclass, qtype); + + /* Truncate the packet. If bug 34346 is present, this + response will be accepted because the final byte (which is + overread) has the expected value, carried over from the + previous response. With bug 34345, the response is + accepted (as NXDOMAIN) because the packet is corrupt. */ + resolv_response_set_buffer (b, + resolv_response_buffer (b), + resolv_response_length (b) - 1); + + } + break; + + case 2: + { + /* Finally, provide a valid response. With either bug + present, this is never reached because the stub resolver + uses the response from the second server above. */ + resolv_response_init (b, (struct resolv_response_flags) {}); + resolv_response_add_question (b, qname, qclass, qtype); + resolv_response_section (b, ns_s_an); + resolv_response_open_record (b, qname, qclass, qtype, 0); + char ipv4[4] = { 192, 0, 2, 17 }; + resolv_response_add_data (b, &ipv4, sizeof (ipv4)); + resolv_response_close_record (b); + } + break; + } +} + +static int +do_test (void) +{ + struct resolv_test *aux = resolv_test_start + ((struct resolv_redirect_config) + { + .response_callback = response, + }); + + /* Reduce test run time. The test hits multiple timeouts as it + switches between name server. */ + _res.retrans = 1; + _res.retry = 1; + + struct addrinfo hints = + { + .ai_family = AF_INET, + .ai_socktype = SOCK_STREAM, + }; + struct addrinfo *ai; + int ret = getaddrinfo ("www.example", "80", &hints, &ai); + check_addrinfo ("www.example", ai, ret, + "address: STREAM/TCP 192.0.2.17 80\n"); + if (ret == 0) + freeaddrinfo (ai); + + resolv_test_end (aux); + + return 0; +} + +#include