Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:dnsmasq
User: [email protected]
Usertags: pu

[ Reason ]
This fixes CVE-2026-12725 and CVE-2026-12969 for trixie. These flaws
have been discovered and fixed upstream in pre-releases of
dnsmasq/2.93, currently in unstable in testing.

[ Impact ]
CVE-2026-12725: A remote attacker able to supply a crafted DNS response
may crash the dnsmasq process, resulting in denial of service.

CVE-2026-12969: A remote attacker controlling a DNS zone can exploit
this via a crafted NXDOMAIN response to cause a 10-byte heap out-of-
bounds read, potentially accessing stale data from prior transactions.

[ Tests ]
In Debian, no tests specific to the affected code have been executed.
However, the changes are cherry-picked from dnsmasq/2.93 which is
already publicly in use. There have been no reports about regressions.

Autopkgtest run successfully locally and on Debusine:
https://debusine.debian.net/debian/developers/work-request/1211374/

[ Risks ]
I consider the risks low as dnsmasq/2.93 is already publicly in use.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in stable
  [x] the issue is verified as fixed in unstable

Sven

-- 
GPG Fingerprint
3DF5 E8AA 43FC 9FDF D086 F195 ADF5 0EDA F8AD D585
diff -Nru dnsmasq-2.91/debian/changelog dnsmasq-2.91/debian/changelog
--- dnsmasq-2.91/debian/changelog	2026-05-02 18:50:46.000000000 +0200
+++ dnsmasq-2.91/debian/changelog	2026-09-01 15:47:50.000000000 +0200
@@ -1,3 +1,11 @@
+dnsmasq (2.91-1+deb13u2) trixie; urgency=medium
+
+  * d/p/*:
+    - CVE-2026-12725.patch: Fix heap-based buffer overflow.
+    - CVE-2026-12969.patch: Fix out-of-bounds read vulnerability.
+
+ -- Sven Geuer <[email protected]>  Tue, 01 Sep 2026 15:47:50 +0200
+
 dnsmasq (2.91-1+deb13u1) trixie-security; urgency=high
 
   * d/p/*:
diff -Nru dnsmasq-2.91/debian/patches/CVE-2026-12725.patch dnsmasq-2.91/debian/patches/CVE-2026-12725.patch
--- dnsmasq-2.91/debian/patches/CVE-2026-12725.patch	1970-01-01 01:00:00.000000000 +0100
+++ dnsmasq-2.91/debian/patches/CVE-2026-12725.patch	2026-09-01 15:47:50.000000000 +0200
@@ -0,0 +1,84 @@
+commit 36d081e37477027fd721fea498f3760f529034ad
+Author: Simon Kelley <[email protected]>
+Date:   Tue Apr 21 22:14:41 2026 +0100
+
+    Fix buffer overlow in log_query()
+    
+    The addition of "(not supported)" to logs of DS and DNSKEY replies
+    overflows the buffer used to construct the string.
+    
+    Re-arrange things to avoid this, and add checks to avoid the same  problem
+    if the logging calls change in the future.
+    
+    Thanks to Yiwei Hou for finding this.
+    
+    The problem exists is DNSSEC is enabled and query logging is also
+    enabled. The overwrite is of bounded length and the bytes
+    written are not in control of an attacker, so this is not considered
+    a likely remote-execution vector.
+
+--- a/src/cache.c
++++ b/src/cache.c
+@@ -2174,7 +2174,7 @@
+     return;
+ 
+   /* build query type string if requested */
+-  if (!(flags & (F_SERVER | F_IPSET)) && type > 0)
++  if (!(flags & (F_SERVER | F_IPSET | F_KEYTAG | F_RR)) && type > 0)
+     arg = querystr(arg, type);
+ 
+   dest = arg;
+@@ -2190,15 +2190,21 @@
+     {
+       dest = daemon->addrbuff;
+ 
+-       if (flags & F_RR)
+-	 {
+-	   if (flags & F_KEYTAG)
+-	     dest = querystr(NULL, addr->rrblock.rrtype);
+-	   else
+-	     dest = querystr(NULL, addr->rrdata.rrtype);
+-	 }
+-       else if (flags & F_KEYTAG)
+-	sprintf(daemon->addrbuff, arg, addr->log.keytag, addr->log.algo, addr->log.digest);
++      if (flags & F_RR)
++	{
++	  if (flags & F_KEYTAG)
++	    dest = querystr(NULL, addr->rrblock.rrtype);
++	  else
++	    dest = querystr(NULL, addr->rrdata.rrtype);
++	}
++#ifdef HAVE_DNSSEC
++      else if (flags & F_KEYTAG)
++	{
++	  snprintf(daemon->addrbuff, ADDRSTRLEN, arg, addr->log.keytag, addr->log.algo, addr->log.digest);
++	  if (type)
++	    extra = " (not supported)";
++	}
++#endif
+       else if (flags & F_RCODE)
+ 	{
+ 	  unsigned int rcode = addr->log.rcode;
+--- a/src/dnssec.c
++++ b/src/dnssec.c
+@@ -955,10 +955,7 @@
+ 			   
+ 			   a.log.keytag = keytag;
+ 			   a.log.algo = algo;
+-			   if (algo_digest_name(algo))
+-			     log_query(F_NOEXTRA | F_KEYTAG | F_UPSTREAM, name, &a, "DNSKEY keytag %hu, algo %hu", 0);
+-			   else
+-			     log_query(F_NOEXTRA | F_KEYTAG | F_UPSTREAM, name, &a, "DNSKEY keytag %hu, algo %hu (not supported)", 0);
++			   log_query(F_NOEXTRA | F_KEYTAG | F_UPSTREAM, name, &a, "DNSKEY keytag %hu, algo %hu", !algo_digest_name(algo));
+ 			 }
+ 		     }
+ 				  
+@@ -1084,7 +1081,7 @@
+ 		  a.log.keytag = keytag;
+ 		  a.log.algo = algo;
+ 		  a.log.digest = digest;
+-		  log_query(F_NOEXTRA | F_KEYTAG | F_UPSTREAM, name, &a, "DS for keytag %hu, algo %hu, digest %hu (not supported)", 0);
++		  log_query(F_NOEXTRA | F_KEYTAG | F_UPSTREAM, name, &a, "DS for keytag %hu, algo %hu, digest %hu", 1);
+ 		  neg_ttl = ttl;
+ 		} 
+ 	      else if ((key = blockdata_alloc((char*)p, rdlen - 4)))
diff -Nru dnsmasq-2.91/debian/patches/CVE-2026-12969.patch dnsmasq-2.91/debian/patches/CVE-2026-12969.patch
--- dnsmasq-2.91/debian/patches/CVE-2026-12969.patch	1970-01-01 01:00:00.000000000 +0100
+++ dnsmasq-2.91/debian/patches/CVE-2026-12969.patch	2026-09-01 15:47:50.000000000 +0200
@@ -0,0 +1,36 @@
+commit 14094e88beca519c53151184cc4553656672b54f
+Author: do litli <[email protected]>
+Date:   Sat May 9 22:21:18 2026 +0100
+
+    Fix buffer OOB read in find_soa()
+    
+    In find_soa() extract_name() is called with extrabytes=0 when parsing NS
+    record names, which means it only validates that the DNS name fits
+    within the packet but does not check that 10 additional bytes exist for
+    the type/class/TTL/rdlen fixed fields. Lines 546-549 then
+    unconditionally read these 10 bytes via GETSHORT/GETLONG macros. An
+    attacker controlling a DNS zone can craft a NXDOMAIN response where the
+    NS record name extends to the packet boundary, causing a 10-byte
+    out-of-bounds read past the valid packet data (CWE-125, CVSS 5.3
+    Medium). The read stays within the over-allocated packet buffer in
+    default configurations, limiting crash risk, but accesses data outside
+    the logical packet boundary. Under certain conditions, the overread may
+    access stale heap data from prior transactions.
+    
+    The fix is straightforward: change the extrabytes
+    argument from 0 to 10, consistent with other call sites in
+    the same file.
+    
+    Credit is due to do litli for finding this problem.
+
+--- a/src/rfc1035.c
++++ b/src/rfc1035.c
+@@ -533,7 +533,7 @@
+   
+   for (i = 0; i < ntohs(header->nscount); i++)
+     {
+-      if (!extract_name(header, qlen, &p, daemon->workspacename, EXTR_NAME_EXTRACT, 0))
++      if (!extract_name(header, qlen, &p, daemon->workspacename, EXTR_NAME_EXTRACT, 10))
+ 	return 0; /* bad packet */
+       
+       GETSHORT(qtype, p); 
diff -Nru dnsmasq-2.91/debian/patches/series dnsmasq-2.91/debian/patches/series
--- dnsmasq-2.91/debian/patches/series	2026-05-02 18:50:46.000000000 +0200
+++ dnsmasq-2.91/debian/patches/series	2026-09-01 15:47:50.000000000 +0200
@@ -6,3 +6,5 @@
 CVE-2026-4892.patch
 CVE-2026-4893.patch
 CVE-2026-5172.patch
+CVE-2026-12725.patch
+CVE-2026-12969.patch

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to