[PATCH v2 3/4] resolv: Fix __libc_res_queriesmatch buffer size argument in send_dg (bug 34346)
Florian Weimer <[email protected]>
| Newsgroups | gmane.comp.lib.glibc.alpha |
|---|---|
| Message-ID | <bc71a9775b0c83be83720292da39dd8ef238ab7c.1786375967.git.fweimer@redhat.com> |
Pass the number of bytes written by recvfrom, not the entire size of the buffer. This is not a security vulnerability because it only allows confirmation of previously existing buffer values. All reads stay within the specified buffer bounds. The buffer contents may not have been initialized. Subsequent processing is correctly capped at buffer bounds, too. Reviewed-by: Adhemerval Zanella <[email protected]> --- resolv/res_send.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/resolv/res_send.c b/resolv/res_send.c index cf27fa7ad6..cc65a03e7d 100644 --- a/resolv/res_send.c +++ b/resolv/res_send.c @@ -1215,14 +1215,14 @@ send_dg(res_state statp, && (skip_query_match || __libc_res_queriesmatch (buf, buf + buflen, *thisansp, - *thisansp + *thisanssizp))) + *thisansp + *thisresplenp))) matching_query = 1; if (!recvresp2 && anhp->id == hp2->id && (skip_query_match || __libc_res_queriesmatch (buf2, buf2 + buflen2, *thisansp, - *thisansp + *thisanssizp))) + *thisansp + *thisresplenp))) matching_query = 2; if (matching_query == 0) /* Spurious UDP packet. Drop it and continue -- 2.55.0