[PATCH] resolv: Count records, and check hostname (CVE-2026-4437, CVE-2026-4438)
Carlos O'Donell
carlos@redhat.com
Fri Mar 20 22:21:43 GMT 2026
On 3/20/26 6:07 PM, Collin Funk wrote:
> Carlos O'Donell <carlos@redhat.com> writes:
>
>>>> + /* Test for invalid UTF-8 characters (2-byte, 4-byte, 6-byte). */
>>>> + { "Invalid use of UTF-8 (2-byte, U+00C0-U+00C2)",
>>>> + "ÁÂÃ.test.ptr.example", NO_RECOVERY, true },
>>>> + { "Invalid use of UTF-8 (4-byte, U+0750-U+0752)",
>>>> + "ݐݑݒ.test.ptr.example", NO_RECOVERY, true },
>>>> + { "Invalid use of UTF-8 (6-byte, U+0904-U+0906)",
>>>> + "ऄअआ.test.ptr.example", NO_RECOVERY, true },
>>> The use of UTF-8 might be tricky to backport for some environments.
>>
>> Windows DNS claims to support UTF-8 characters in names:
>> https://learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/naming-conventions-for-computer-domain-site-ou
>>
>> So I wanted to include a test that showed UTF-8 as invalid since our
>> implementation doesn't currently support it.
>>
>> My preference is to leave them, and if they are difficult to backport we
>> can revisit a simplified or alternate test that encodes them in a
>> different way?
>
> It is less readable, but what we do in Gnulib is just write the UTF-8
> characters in bytes. For example, "ऄअआ" would be written as
> "\xE0\xA4\x84\xE0\xA4\x85\xE0\xA4\x86".
And error prone.
I have a strong opinion here, and I think we should do one of these:
(a) Use UTF-8 directly.
(b) Build up support/* infrastructure to specify codepoints
that can be inserted to build the final string.
Thoughts?
--
Cheers,
Carlos.
More information about the Libc-alpha
mailing list