[PATCH v2 3/4] resolv: Fix __libc_res_queriesmatch buffer size argument in send_dg (bug 34346)

Florian Weimer <[email protected]>
Newsgroups gmane.comp.lib.glibc.alpha
Message-ID <bc71a9775b0c83be83720292da39dd8ef238ab7c.1786375967.git.fweimer@redhat.com>
Pass the number of bytes written by recvfrom, not the entire size
of the buffer.

This is not a security vulnerability because it only allows
confirmation of previously existing buffer values.  All reads stay
within the specified buffer bounds.  The buffer contents may not have
been initialized.  Subsequent processing is correctly capped at buffer
bounds, too.

Reviewed-by: Adhemerval Zanella <[email protected]>
---
 resolv/res_send.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/resolv/res_send.c b/resolv/res_send.c
index cf27fa7ad6..cc65a03e7d 100644
--- a/resolv/res_send.c
+++ b/resolv/res_send.c
@@ -1215,14 +1215,14 @@ send_dg(res_state statp,
 		    && (skip_query_match
 			|| __libc_res_queriesmatch (buf, buf + buflen,
 						    *thisansp,
-						    *thisansp + *thisanssizp)))
+						    *thisansp + *thisresplenp)))
 		  matching_query = 1;
 		if (!recvresp2
 		    && anhp->id == hp2->id
 		    && (skip_query_match
 			|| __libc_res_queriesmatch (buf2, buf2 + buflen2,
 						    *thisansp,
-						    *thisansp + *thisanssizp)))
+						    *thisansp + *thisresplenp)))
 		  matching_query = 2;
 		if (matching_query == 0)
 		  /* Spurious UDP packet.  Drop it and continue
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.