diff options
| author | Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com> | 2026-05-18 22:43:34 +0530 |
|---|---|---|
| committer | Khem Raj <khem.raj@oss.qualcomm.com> | 2026-05-20 21:18:31 -0700 |
| commit | 21c3d7eb6f94f967b5e02fc61cc027d3893764a0 (patch) | |
| tree | 4b1c4d5237d34b87d43e59f117a369cb4f9487c2 /meta-networking/recipes-support | |
| parent | a9de48a9fa55a254c0bf2eb528c81bd90e015c03 (diff) | |
| download | meta-openembedded-21c3d7eb6f94f967b5e02fc61cc027d3893764a0.tar.gz | |
dnsmasq: fix CVE-2026-4892
A heap-based out-of-bounds write vulnerability in the DHCPv6
implementation of dnsmasq allows local attackers to execute
arbitrary code with root privileges via a crafted DHCPv6 packet.
Reference:
[ https://nvd.nist.gov/vuln/detail/CVE-2026-4892 ]
Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com>
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>
Diffstat (limited to 'meta-networking/recipes-support')
| -rw-r--r-- | meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb | 1 | ||||
| -rw-r--r-- | meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch | 36 |
2 files changed, 37 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb index 850bfd2657..cf900328ed 100644 --- a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb +++ b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb | |||
| @@ -18,6 +18,7 @@ SRC_URI = "http://www.thekelleys.org.uk/dnsmasq/${@['archive/', ''][float(d.getV | |||
| 18 | file://CVE-2026-2291.patch \ | 18 | file://CVE-2026-2291.patch \ |
| 19 | file://CVE-2026-4890.patch \ | 19 | file://CVE-2026-4890.patch \ |
| 20 | file://CVE-2026-4891.patch \ | 20 | file://CVE-2026-4891.patch \ |
| 21 | file://CVE-2026-4892.patch \ | ||
| 21 | " | 22 | " |
| 22 | SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1" | 23 | SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1" |
| 23 | 24 | ||
diff --git a/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch new file mode 100644 index 0000000000..01637601a3 --- /dev/null +++ b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch | |||
| @@ -0,0 +1,36 @@ | |||
| 1 | commit 011a36c51438c986535a7248ed2e7f424f8e1078 | ||
| 2 | Author: Simon Kelley <simon@thekelleys.org.uk> | ||
| 3 | Date: Wed Mar 25 23:16:35 2026 +0000 | ||
| 4 | |||
| 5 | Fix buffer overflow in helper.c with large CLIDs. CVE-2026-4892 | ||
| 6 | |||
| 7 | Bug reported bt Royce M <royce@xchglabs.com> | ||
| 8 | |||
| 9 | Location: helper.c:265-270 | ||
| 10 | DHCPv6 CLIDs can be up to 65535 bytes. When --dhcp-script is configured, | ||
| 11 | the helper hex-encodes raw CLID bytes via sprintf("%.2x") into daemon->packet (5131 bytes). | ||
| 12 | A 1000-byte CLID writes ~3000 bytes. The helper process retains root privileges. | ||
| 13 | |||
| 14 | Note: log6_packet() correctly caps CLID to 100 bytes for logging, but the helper code path was missed. | ||
| 15 | |||
| 16 | CVE: CVE-2026-4892 | ||
| 17 | |||
| 18 | Upstream-Status: Backport [ https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=10e6b5b83e80749cba7b090d7780b29f908f0571 ] | ||
| 19 | |||
| 20 | Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com> | ||
| 21 | |||
| 22 | diff --git a/src/helper.c b/src/helper.c | ||
| 23 | index 72f81fe..2c12801 100644 | ||
| 24 | --- a/src/helper.c | ||
| 25 | +++ b/src/helper.c | ||
| 26 | @@ -261,8 +261,8 @@ int create_helper(int event_fd, int err_fd, uid_t uid, gid_t gid, long max_fd) | ||
| 27 | data.hostname_len + data.ed_len + data.clid_len, RW_READ)) | ||
| 28 | continue; | ||
| 29 | |||
| 30 | - /* CLID into packet */ | ||
| 31 | - for (p = daemon->packet, i = 0; i < data.clid_len; i++) | ||
| 32 | + /* CLID into packet: limit to 100 bytes to avoid overflowing buffer. */ | ||
| 33 | + for (p = daemon->packet, i = 0; i < data.clid_len && i < 100; i++) | ||
| 34 | { | ||
| 35 | p += sprintf(p, "%.2x", buf[i]); | ||
| 36 | if (i != data.clid_len - 1) | ||
