diff options
Diffstat (limited to 'meta-networking/recipes-support')
| -rw-r--r-- | meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb | 1 | ||||
| -rw-r--r-- | meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch | 36 |
2 files changed, 37 insertions, 0 deletions
diff --git a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb index 850bfd2657..cf900328ed 100644 --- a/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb +++ b/meta-networking/recipes-support/dnsmasq/dnsmasq_2.92.bb | |||
| @@ -18,6 +18,7 @@ SRC_URI = "http://www.thekelleys.org.uk/dnsmasq/${@['archive/', ''][float(d.getV | |||
| 18 | file://CVE-2026-2291.patch \ | 18 | file://CVE-2026-2291.patch \ |
| 19 | file://CVE-2026-4890.patch \ | 19 | file://CVE-2026-4890.patch \ |
| 20 | file://CVE-2026-4891.patch \ | 20 | file://CVE-2026-4891.patch \ |
| 21 | file://CVE-2026-4892.patch \ | ||
| 21 | " | 22 | " |
| 22 | SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1" | 23 | SRC_URI[sha256sum] = "fd908e79ff37f73234afcb6d3363f78353e768703d92abd8e3220ade6819b1e1" |
| 23 | 24 | ||
diff --git a/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch new file mode 100644 index 0000000000..01637601a3 --- /dev/null +++ b/meta-networking/recipes-support/dnsmasq/files/CVE-2026-4892.patch | |||
| @@ -0,0 +1,36 @@ | |||
| 1 | commit 011a36c51438c986535a7248ed2e7f424f8e1078 | ||
| 2 | Author: Simon Kelley <simon@thekelleys.org.uk> | ||
| 3 | Date: Wed Mar 25 23:16:35 2026 +0000 | ||
| 4 | |||
| 5 | Fix buffer overflow in helper.c with large CLIDs. CVE-2026-4892 | ||
| 6 | |||
| 7 | Bug reported bt Royce M <royce@xchglabs.com> | ||
| 8 | |||
| 9 | Location: helper.c:265-270 | ||
| 10 | DHCPv6 CLIDs can be up to 65535 bytes. When --dhcp-script is configured, | ||
| 11 | the helper hex-encodes raw CLID bytes via sprintf("%.2x") into daemon->packet (5131 bytes). | ||
| 12 | A 1000-byte CLID writes ~3000 bytes. The helper process retains root privileges. | ||
| 13 | |||
| 14 | Note: log6_packet() correctly caps CLID to 100 bytes for logging, but the helper code path was missed. | ||
| 15 | |||
| 16 | CVE: CVE-2026-4892 | ||
| 17 | |||
| 18 | Upstream-Status: Backport [ https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=10e6b5b83e80749cba7b090d7780b29f908f0571 ] | ||
| 19 | |||
| 20 | Signed-off-by: Abhishek Bachiphale <Abhishek.Bachiphale@windriver.com> | ||
| 21 | |||
| 22 | diff --git a/src/helper.c b/src/helper.c | ||
| 23 | index 72f81fe..2c12801 100644 | ||
| 24 | --- a/src/helper.c | ||
| 25 | +++ b/src/helper.c | ||
| 26 | @@ -261,8 +261,8 @@ int create_helper(int event_fd, int err_fd, uid_t uid, gid_t gid, long max_fd) | ||
| 27 | data.hostname_len + data.ed_len + data.clid_len, RW_READ)) | ||
| 28 | continue; | ||
| 29 | |||
| 30 | - /* CLID into packet */ | ||
| 31 | - for (p = daemon->packet, i = 0; i < data.clid_len; i++) | ||
| 32 | + /* CLID into packet: limit to 100 bytes to avoid overflowing buffer. */ | ||
| 33 | + for (p = daemon->packet, i = 0; i < data.clid_len && i < 100; i++) | ||
| 34 | { | ||
| 35 | p += sprintf(p, "%.2x", buf[i]); | ||
| 36 | if (i != data.clid_len - 1) | ||
