[glibc] resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345)

Florian Weimer via Glibc-cvs <[email protected]>
Newsgroups gmane.comp.lib.glibc.cvs
Message-ID <[email protected]>
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=1960326bb63e040a2eb9fbb1f322bec90439d3fc

commit 1960326bb63e040a2eb9fbb1f322bec90439d3fc
Author: Florian Weimer <[email protected]>
Date:   Sat Aug 15 12:03:35 2026 +0200

    resolv: Handle ternary return value in __libc_res_queriesmatch (bug 34345)
    
    The __libc_res_nameinquery function returns -1 for corrupted packets.
    The previous code treated those as matching.
    
    This is not a security vulnerability because the transaction ID is
    still checked.  The bug does not  make off-path attacks substantially
    easier.  Furthermore, most users of the DNS stub resolver parse the
    question name again, and do not simply skip over it using dn_skipname
    or similar (which would hide the corruption).  This means that the
    packet is still rejected at a later stage.
    
    Reviewed-by: Adhemerval Zanella <[email protected]>

Diff:
---
 resolv/res_queriesmatch.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/resolv/res_queriesmatch.c b/resolv/res_queriesmatch.c
index 08d82f1814..a11d0b4fc7 100644
--- a/resolv/res_queriesmatch.c
+++ b/resolv/res_queriesmatch.c
@@ -122,7 +122,8 @@ __libc_res_queriesmatch (const unsigned char *buf1, const unsigned char *eom1,
         return -1;
       NS_GET16 (ttype, cp);
       NS_GET16 (tclass, cp);
-      if (!__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2))
+      if (__libc_res_nameinquery (tname, ttype, tclass, buf2, eom2) <= 0)
+        /* Parse error or mismatch.  */
         return 0;
     }
   return 1;
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.