[Bug network/34033] resolv/ns_print.c: ns_sprintrrf TSIG path bypasses buflen and can overflow caller buffer

"cvs-commit at gcc dot gnu.org via Glibc-bugs" <[email protected]> Fri, 19 Jun 2026 17:00:25 +0000
Newsgroups gmane.comp.lib.glibc.bugs
Message-ID <[email protected]/bugzilla/>
https://sourceware.org/bugzilla/show_bug.cgi?id=34033

--- Comment #7 from Sourceware Commits <cvs-commit at gcc dot gnu.org> ---
The master branch has been updated by Florian Weimer <[email protected]>:

https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=ca44a6609c29a683b03575fa035c6d17aa591e72

commit ca44a6609c29a683b03575fa035c6d17aa591e72
Author: Florian Weimer <[email protected]>
Date:   Fri Jun 19 18:22:20 2026 +0200

    resolv: More types as unknown in ns_sprintrrf (CVE-2026-5435)

    Specifically, CERT, TKEY, TSIG, OPT.  This removes the buggy
    implementations of TSIG, fixing bug 34033, and partially
    fixing bug 34069.

    Reviewed-by: Carlos O'Donell <[email protected]>
    Reviewed-by: Adhemerval Zanella <[email protected]>

-- 
You are receiving this mail because:
You are on the CC list for the bug.