Re: [BLFS Trac] #23619: Net-DNS-1.56 (Perl module)

BLFS Trac ([email protected] via blfs-book Mailing List) <[email protected]> Mon, 20 Jul 2026 19:07:57 -0000
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23619: Net-DNS-1.56 (Perl module)
-------------------------+-------------------------------
 Reporter:  Bruce Dubbs  |       Owner:  SecurityAdvisory
     Type:  enhancement  |      Status:  new
 Priority:  elevated     |   Milestone:  98-Security
Component:  BOOK         |     Version:  git
 Severity:  normal       |  Resolution:
 Keywords:               |
-------------------------+-------------------------------
Comment (by Joe Locash):

 {{{
 Message-ID: <[email protected]>
 Date: Mon, 20 Jul 2026 18:56:51 +0100
 From: Robert Rothenberg <[email protected]>
 To: [email protected], [email protected]
 Subject: CVE-2026-64193: Net::DNS versions through 1.55 for Perl allow
 remote
  execution injection via EDNS EXTENDED ERROR


 ========================================================================
 CVE-2026-64193                                       CPAN Security Group
 ========================================================================

          CVE ID:  CVE-2026-64193
    Distribution:  Net-DNS
        Versions:  through 1.55

        MetaCPAN:  https://metacpan.org/dist/Net-DNS
        VCS Repo:  https://www.net-dns.org/svn/net-dns/


 Net::DNS versions through 1.55 for Perl allow remote execution
 injection via EDNS EXTENDED ERROR

 Description
 -----------
 Net::DNS versions through 1.55 for Perl allow remote execution
 injection via EDNS EXTENDED ERROR.

 Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT
 field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw
 bytes and passing the result to Perl's eval. There is some escaping
 done for $ and @, but not for backticks. This can be exploited for
 command execution if $pkt->edns->option('EXTENDED-ERROR') is called in
 array context, for example with a payload of {0:`"<command>"`} in
 EXTRA-TEXT.

 Problem types
 -------------
 - CWE-95 Improper Neutralization of Directives in Dynamically Evaluated
    Code ('Eval Injection')

 Solutions
 ---------
 Upgrade to version 1.56 or later.


 References
 ----------
 https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56
 https://rt.cpan.org/Ticket/Display.html?id=179945
 https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes

 Timeline
 --------
 - 2026-07-10: Issue reported publicly via RT.
 - 2026-07-10: Version 1.55_01 (release candidate for version 1.56)
    published on CPAN.
 - 2026-07-18: Version 1.56 published on CPAN.

 Credits
 -------
 Steffen Ullrich, reporter
 }}}

 {{{
 Message-ID: <[email protected]>
 Date: Mon, 20 Jul 2026 18:56:09 +0100
 From: Robert Rothenberg <[email protected]>
 To: [email protected], [email protected]
 Subject: CVE-2026-64194: Net::DNS versions through 1.55 for Perl allow
 Denial
  of Service via deep DNS compression pointer chains


 ========================================================================
 CVE-2026-64194                                       CPAN Security Group
 ========================================================================

          CVE ID:  CVE-2026-64194
    Distribution:  Net-DNS
        Versions:  through 1.55

        MetaCPAN:  https://metacpan.org/dist/Net-DNS
        VCS Repo:  https://www.net-dns.org/svn/net-dns/


 Net::DNS versions through 1.55 for Perl allow Denial of Service via
 deep DNS compression pointer chains

 Description
 -----------
 Net::DNS versions through 1.55 for Perl allow Denial of Service via
 deep DNS compression pointer chains.

 Net::DNS::DomainName::decode follows RFC 1035 compression pointers by
 recursing into itself with no depth limit. It is possible to construct
 a name which saturates the call stack (at least with larger TCP
 responses), leading to a potential Denial of Service.

 The guard `$link < $offset` prevents forward and circular chains, but
 still allows arbitrarily long backward chains. The per-offset cache
 (`$cache`) is populated at the start of each call and short-circuits
 only re-traverses of the same offset - the initial descent through a
 fresh chain still recurses at full depth.

 A crafted packet can chain two-byte compression pointers so that each
 one points two bytes earlier than the previous, producing a chain
 length of `offset / 2`. For the 14-bit pointer field (max offset 16383)
 this gives up to ~8191 recursive frames. For a TCP DNS message the
 limit is the 16-bit length field (~32767 frames). Perl's default C
 stack handles only a few thousand frames; beyond that the process
 receives SIGSEGV or similar, which is a denial-of-service for any
 application parsing untrusted DNS data.

 The vulnerability is triggered by `Net::DNS::Packet->new(\$wire)` i.e.
 any point where the library decodes a DNS message from the network.

 Problem types
 -------------
 - CWE-674 Uncontrolled Recursion

 Solutions
 ---------
 Upgrade to version 1.56 or later.


 References
 ----------
 https://www.net-dns.org/blog/#release-candidate-for-netdns-1.56
 https://rt.cpan.org/Ticket/Display.html?id=179946
 https://metacpan.org/release/NLNETLABS/Net-DNS-1.55_01/changes

 Timeline
 --------
 - 2026-07-10: Issue reported publicly via RT.
 - 2026-07-10: Version 1.55_01 (release candidate for version 1.56)
    published on CPAN.
 - 2026-07-18: Version 1.56 published on CPAN.

 Credits
 -------
 Steffen Ullrich, reporter
 }}}
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23619#comment:3>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page