diff options
| author | Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com> | 2026-05-23 17:00:21 +1200 |
|---|---|---|
| committer | Anuj Mittal <anuj.mittal@oss.qualcomm.com> | 2026-05-29 09:29:30 +0530 |
| commit | 81572e132c1f78b8c153ded144f808f8a828e6c2 (patch) | |
| tree | 90bf5620f6fed3b097a97e0443777286d501e35e | |
| parent | 82dc5548d5c018d811c7d92d52dee4be53be4549 (diff) | |
| download | meta-openembedded-81572e132c1f78b8c153ded144f808f8a828e6c2.tar.gz | |
dnsmasq: fix CVE-2026-4891
A heap-based out-of-bounds read vulnerability in the
DNSSEC validation of dnsmasq allows remote attackers
to cause a denial of service via a crafted DNS packet.
Reference:
[ https://nvd.nist.gov/vuln/detail/CVE-2026-4891 ]
Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
(cherry picked from commit a9de48a9fa55a254c0bf2eb528c81bd90e015c03)
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
| -rw-r--r-- | meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb | 1 | ||||
| -rw-r--r-- | meta-networking/recipes-support/dnsmasq/files/CVE-2026-4891.patch | 40 |
2 files changed, 41 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb index 59509ecba2..0de434036a 100644 --- a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb +++ b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb | |||
| @@ -15,6 +15,7 @@ SRC_URI = "http://www.thekelleys.org.uk/dnsmasq/${@['archive/', ''][float(d.getV | |||
| 15 | file://dnsmasq-resolvconf.service \ | 15 | file://dnsmasq-resolvconf.service \ |
| 16 | file://dnsmasq-noresolvconf.service \ | 16 | file://dnsmasq-noresolvconf.service \ |
| 17 | file://dnsmasq-resolved.conf \ | 17 | file://dnsmasq-resolved.conf \ |
| 18 | file://CVE-2026-4891.patch \ | ||
| 18 | " | 19 | " |
| 19 | SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1" | 20 | SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1" |
| 20 | 21 | ||
diff --git a/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4891.patch b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4891.patch new file mode 100644 index 0000000000..e721f5ec0b --- /dev/null +++ b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4891.patch | |||
| @@ -0,0 +1,40 @@ | |||
| 1 | commit 2cacea42e4d45717bd0ce3ccfe8e78960245e5da | ||
| 2 | Author: Simon Kelley <simon@thekelleys.org.uk> | ||
| 3 | Date: Wed Mar 25 23:04:08 2026 +0000 | ||
| 4 | |||
| 5 | Verify rdlen field in RRSIG packets. CVE-2026-4891 | ||
| 6 | |||
| 7 | Bug report from Royce M <royce@xchglabs.com> | ||
| 8 | |||
| 9 | This avoids crafted packets which give a value for rdlen _less_ | ||
| 10 | then the space taken up by the fixed data and the signer's name | ||
| 11 | and engender a negative calculated length for the signature. | ||
| 12 | |||
| 13 | CVE: CVE-2026-4891 | ||
| 14 | |||
| 15 | Upstream-Status: Backport [ https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=788b4e0f6c05217981b512bed4e5fea6f8855d01 ] | ||
| 16 | |||
| 17 | Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com> | ||
| 18 | |||
| 19 | diff --git a/src/dnssec.c b/src/dnssec.c | ||
| 20 | index 0860daa..4bb0495 100644 | ||
| 21 | --- a/src/dnssec.c | ||
| 22 | +++ b/src/dnssec.c | ||
| 23 | @@ -546,10 +546,14 @@ static int validate_rrset(time_t now, struct dns_header *header, size_t plen, in | ||
| 24 | |||
| 25 | *ttl_out = ttl; | ||
| 26 | } | ||
| 27 | - | ||
| 28 | + | ||
| 29 | + /* Don't trust rdlen not to be too small and give us a negative sig_len | ||
| 30 | + It has already been checked that it doesn't run us off the end | ||
| 31 | + of the packet. */ | ||
| 32 | + if ((sig_len = rdlen - (p - psav)) <= 0) | ||
| 33 | + return STAT_BOGUS; | ||
| 34 | + | ||
| 35 | sig = p; | ||
| 36 | - sig_len = rdlen - (p - psav); | ||
| 37 | - | ||
| 38 | nsigttl = htonl(orig_ttl); | ||
| 39 | |||
| 40 | hash->update(ctx, 18, psav); | ||
