[PATCH v2 2/4] resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345)

Florian Weimer <[email protected]>
Newsgroups gmane.comp.lib.glibc.alpha
Message-ID <d1df5e3ff30134df4b43672dd46f54a159bd4241.1786375967.git.fweimer@redhat.com>
The __libc_res_nameinquery function returns -1 for corrupted packets.
The previous code treated those as matching.

This is not a security vulnerability because the transaction ID is
still checked.  The bug does not  make off-path attacks substantially
easier.  Furthermore, most users of the DNS stub resolver parse the
question name again, and do not simply skip over it using dn_skipname
or similar (which would hide the corruption).  This means that the
packet is still rejected at a later stage.

Reviewed-by: Adhemerval Zanella <[email protected]>
---
 resolv/res_queriesmatch.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/resolv/res_queriesmatch.c b/resolv/res_queriesmatch.c
index 08d82f1814..a11d0b4fc7 100644
--- a/resolv/res_queriesmatch.c
+++ b/resolv/res_queriesmatch.c
@@ -122,7 +122,8 @@ __libc_res_queriesmatch (const unsigned char *buf1, const unsigned char *eom1,
         return -1;
       NS_GET16 (ttype, cp);
       NS_GET16 (tclass, cp);
-      if (!__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2))
+      if (__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2) <= 0)
+        /* Parse error or mismatch.  */
         return 0;
     }
   return 1;
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.