Re: [PATCH 2/4] resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345)

Adhemerval Zanella Netto <[email protected]> Tue, 28 Jul 2026 15:10:48 -0300
Newsgroups gmane.comp.lib.glibc.alpha
Organization Linaro
Message-ID <[email protected]>

On 03/07/26 11:52, Florian Weimer wrote:
> The __libc_res_nameinquery function returns -1 for corrupted packets.
> The previous code treated those as matching.
> 
> This is not a security vulnerability because the transaction ID is
> still checked.  The bug does not  make off-path attacks substantially
> easier.  Furthermore, most users of the DNS stub resolver parse the
> question name again, and do not simply skip over it using dn_skipname
> or similar (which would hide the corruption).  This means that the
> packet is still rejected at a later stage.

LGTM, thanks.

Reviewed-by: Adhemerval Zanella  <[email protected]>

> ---
>  resolv/res_queriesmatch.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/resolv/res_queriesmatch.c b/resolv/res_queriesmatch.c
> index 08d82f1814..a11d0b4fc7 100644
> --- a/resolv/res_queriesmatch.c
> +++ b/resolv/res_queriesmatch.c
> @@ -122,7 +122,8 @@ __libc_res_queriesmatch (const unsigned char *buf1, const unsigned char *eom1,
>          return -1;
>        NS_GET16 (ttype, cp);
>        NS_GET16 (tclass, cp);
> -      if (!__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2))
> +      if (__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2) <= 0)
> +        /* Parse error or mismatch.  */
>          return 0;
>      }
>    return 1;