Re: [PATCH 2/4] resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345)
Adhemerval Zanella Netto <[email protected]> Tue, 28 Jul 2026 15:10:48 -0300
| Newsgroups | gmane.comp.lib.glibc.alpha |
|---|---|
| Organization | Linaro |
| Message-ID | <[email protected]> |
On 03/07/26 11:52, Florian Weimer wrote: > The __libc_res_nameinquery function returns -1 for corrupted packets. > The previous code treated those as matching. > > This is not a security vulnerability because the transaction ID is > still checked. The bug does not make off-path attacks substantially > easier. Furthermore, most users of the DNS stub resolver parse the > question name again, and do not simply skip over it using dn_skipname > or similar (which would hide the corruption). This means that the > packet is still rejected at a later stage. LGTM, thanks. Reviewed-by: Adhemerval Zanella <[email protected]> > --- > resolv/res_queriesmatch.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/resolv/res_queriesmatch.c b/resolv/res_queriesmatch.c > index 08d82f1814..a11d0b4fc7 100644 > --- a/resolv/res_queriesmatch.c > +++ b/resolv/res_queriesmatch.c > @@ -122,7 +122,8 @@ __libc_res_queriesmatch (const unsigned char *buf1, const unsigned char *eom1, > return -1; > NS_GET16 (ttype, cp); > NS_GET16 (tclass, cp); > - if (!__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2)) > + if (__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2) <= 0) > + /* Parse error or mismatch. */ > return 0; > } > return 1;