[PATCH] resolv: Fix assertion failure on search list truncation [BZ 31026, CVE-2026-8674]

Florian Weimer fweimer@redhat.com
Tue Sep 15 11:11:44 GMT 2026


* Adhemerval Zanella:

> update_from_conf copies the search list into the 256-byte
> resp->defdname and truncates it when an entry does not fit, then
> asserts that resolv_conf_matches accepts the result.
>
> The truncation check there compared the accumulated size against
> sizeof (resp->dnsrch) (the pointer array) instead of resp->defdname,
> and the empty-list case did not account for a first entry that does
> not fit at all.  A long search domain in resolv.conf or LOCALDOMAIN
> thus aborts any process using the resolver.
>
> Check whether the entry fits in the remaining defdname space, matching
> alloc_buffer_copy_string, and also accept an empty resp->dnsrch when
> the first entry is too long.  Add tests covering both cases through
> the search and domain directives.

Why is this considered a vulnerability?  I can see that this data can
come from DHCP, but DHCP can easily serve bad name servers, and then
name resolution is busted, too.

Is the concern that once the system has learned the bad data, it won't
boo anymore?

The patch iself looks okay.

Reviewed-by: Florian Weimer <fweimer@redhat.com>

Thanks,
Florian



More information about the Libc-alpha mailing list