[PATCH 3/4] resolv: Fix __libc_res_queriesmatch buffer size argument in send_dg (bug 34346)

Adhemerval Zanella Netto adhemerval.zanella@linaro.org
Tue Jul 28 18:11:08 GMT 2026



On 03/07/26 11:53, Florian Weimer wrote:
> Pass the number of bytes written by recvfrom, not the entire size
> of the buffer.
> 
> This is not a security vulnerability because it only allows
> confirmation of previously existing buffer values.  All reads stay
> within the specified buffer bounds.  The buffer contents may not have
> been initialized.  Subsequent processing is correctly capped at buffer
> bounds, too.


LGTM, thanks.

Reviewed-by: Adhemerval Zanella  <adhemerval.zanella@linaro.org>

> ---
>  resolv/res_send.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/resolv/res_send.c b/resolv/res_send.c
> index cf27fa7ad6..cc65a03e7d 100644
> --- a/resolv/res_send.c
> +++ b/resolv/res_send.c
> @@ -1215,14 +1215,14 @@ send_dg(res_state statp,
>  		    && (skip_query_match
>  			|| __libc_res_queriesmatch (buf, buf + buflen,
>  						    *thisansp,
> -						    *thisansp + *thisanssizp)))
> +						    *thisansp + *thisresplenp)))
>  		  matching_query = 1;
>  		if (!recvresp2
>  		    && anhp->id == hp2->id
>  		    && (skip_query_match
>  			|| __libc_res_queriesmatch (buf2, buf2 + buflen2,
>  						    *thisansp,
> -						    *thisansp + *thisanssizp)))
> +						    *thisansp + *thisresplenp)))
>  		  matching_query = 2;
>  		if (matching_query == 0)
>  		  /* Spurious UDP packet.  Drop it and continue



More information about the Libc-alpha mailing list