Re: [PATCH 3/4] resolv: Fix __libc_res_queriesmatch buffer size argument in send_dg (bug 34346)
Adhemerval Zanella Netto <[email protected]> Tue, 28 Jul 2026 15:11:08 -0300
| Newsgroups | gmane.comp.lib.glibc.alpha |
|---|---|
| Organization | Linaro |
| Message-ID | <[email protected]> |
On 03/07/26 11:53, Florian Weimer wrote: > Pass the number of bytes written by recvfrom, not the entire size > of the buffer. > > This is not a security vulnerability because it only allows > confirmation of previously existing buffer values. All reads stay > within the specified buffer bounds. The buffer contents may not have > been initialized. Subsequent processing is correctly capped at buffer > bounds, too. LGTM, thanks. Reviewed-by: Adhemerval Zanella <[email protected]> > --- > resolv/res_send.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/resolv/res_send.c b/resolv/res_send.c > index cf27fa7ad6..cc65a03e7d 100644 > --- a/resolv/res_send.c > +++ b/resolv/res_send.c > @@ -1215,14 +1215,14 @@ send_dg(res_state statp, > && (skip_query_match > || __libc_res_queriesmatch (buf, buf + buflen, > *thisansp, > - *thisansp + *thisanssizp))) > + *thisansp + *thisresplenp))) > matching_query = 1; > if (!recvresp2 > && anhp->id == hp2->id > && (skip_query_match > || __libc_res_queriesmatch (buf2, buf2 + buflen2, > *thisansp, > - *thisansp + *thisanssizp))) > + *thisansp + *thisresplenp))) > matching_query = 2; > if (matching_query == 0) > /* Spurious UDP packet. Drop it and continue