summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorAbhishek Bachiphale <Abhishek.Bachiphale@windriver.com>2026-05-18 22:43:31 +0530
committerKhem Raj <khem.raj@oss.qualcomm.com>2026-05-20 21:18:30 -0700
commita53328688a239e97b8383ffbfd7b4b4eca108d73 (patch)
treebb83d7aeea464971800c4d73cd923f14d971a5c3
parent47e9739586748a60428a116c0dcd761a2f648588 (diff)
downloadmeta-openembedded-a53328688a239e97b8383ffbfd7b4b4eca108d73.tar.gz
dnsmasq: fix CVE-2026-2291
dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-controlled IP address, or to cause a DoS. Reference: [ https://nvd.nist.gov/vuln/detail/CVE-2026-2291 ] Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
-rw-r--r--meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb1
-rw-r--r--meta-networking/recipes-support/dnsmasq/files/CVE-2026-2291.patch37
2 files changed, 38 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb
index 59509ecba2..bef058aa3e 100644
--- a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb
+++ b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb
@@ -15,6 +15,7 @@ SRC_URI = "http://www.thekelleys.org.uk/dnsmasq/${@['archive/', ''][float(d.getV
15 file://dnsmasq-resolvconf.service \ 15 file://dnsmasq-resolvconf.service \
16 file://dnsmasq-noresolvconf.service \ 16 file://dnsmasq-noresolvconf.service \
17 file://dnsmasq-resolved.conf \ 17 file://dnsmasq-resolved.conf \
18 file://CVE-2026-2291.patch \
18" 19"
19SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1" 20SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1"
20 21
diff --git a/meta-networking/recipes-support/dnsmasq/files/CVE-2026-2291.patch b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-2291.patch
new file mode 100644
index 0000000000..6e42f32136
--- /dev/null
+++ b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-2291.patch
@@ -0,0 +1,37 @@
1commit ec2fbfbbdaa7d7db1c707dce26ce1a37cfe09660
2Author: Simon Kelley <simon@thekelleys.org.uk>
3Date: Fri Apr 10 16:29:31 2026 +0100
4
5Fix buffer overflow in struct bigname. CVE-2026-2291
6
7All buffers capable of holding a domain name should be
8at least MAXDNAME*2 + 1 bytes long, where MAXDNAME is the maximum
9size of a domain name. The accounts for the trailing zero and the
10fact that some characters are escaped in the internal representation
11of a domain name in dnsmasq.
12
13The declaration of struct bigname get this wrong, with the effect
14that a remote attacker capable of asking DNS queries or answering DNS
15queries can cause a large OOB write in the heap.
16
17This was first spotted by Andrew S. Fasano.
18
19CVE: CVE-2026-2291
20
21Upstream-Status: Backport [ https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=014e909f787e808bb35daa546d3f8f3663918de2 ]
22
23Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
24
25diff --git a/src/dnsmasq.h b/src/dnsmasq.h
26index 254bacd..58be09f 100644
27--- a/src/dnsmasq.h
28+++ b/src/dnsmasq.h
29@@ -479,7 +479,7 @@ struct interface_name {
30 };
31
32 union bigname {
33- char name[MAXDNAME];
34+ char name[(2*MAXDNAME) + 1];
35 union bigname *next; /* freelist */
36 };
37