[glibc] resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345)
Florian Weimer via Glibc-cvs <[email protected]>
| Newsgroups | gmane.comp.lib.glibc.cvs |
|---|---|
| Message-ID | <[email protected]> |
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=1960326bb63e040a2eb9fbb1f322bec90439d3fc commit 1960326bb63e040a2eb9fbb1f322bec90439d3fc Author: Florian Weimer <[email protected]> Date: Sat Aug 15 12:03:35 2026 +0200 resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345) The __libc_res_nameinquery function returns -1 for corrupted packets. The previous code treated those as matching. This is not a security vulnerability because the transaction ID is still checked. The bug does not make off-path attacks substantially easier. Furthermore, most users of the DNS stub resolver parse the question name again, and do not simply skip over it using dn_skipname or similar (which would hide the corruption). This means that the packet is still rejected at a later stage. Reviewed-by: Adhemerval Zanella <[email protected]> Diff: --- resolv/res_queriesmatch.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/resolv/res_queriesmatch.c b/resolv/res_queriesmatch.c index 08d82f1814..a11d0b4fc7 100644 --- a/resolv/res_queriesmatch.c +++ b/resolv/res_queriesmatch.c @@ -122,7 +122,8 @@ __libc_res_queriesmatch (const unsigned char *buf1, const unsigned char *eom1, return -1; NS_GET16 (ttype, cp); NS_GET16 (tclass, cp); - if (!__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2)) + if (__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2) <= 0) + /* Parse error or mismatch. */ return 0; } return 1;