Hello community,

here is the log from the commit of package dnsmasq for openSUSE:Leap:15.2 
checked in at 2020-03-21 16:42:41
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Leap:15.2/dnsmasq (Old)
 and      /work/SRC/openSUSE:Leap:15.2/.dnsmasq.new.3160 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "dnsmasq"

Sat Mar 21 16:42:41 2020 rev:20 rq:754915 version:2.78

Changes:
--------
--- /work/SRC/openSUSE:Leap:15.2/dnsmasq/dnsmasq.changes        2020-01-15 
14:52:36.317495357 +0100
+++ /work/SRC/openSUSE:Leap:15.2/.dnsmasq.new.3160/dnsmasq.changes      
2020-03-21 16:42:42.465373734 +0100
@@ -1,0 +2,18 @@
+Wed Nov 13 10:23:27 UTC 2019 - Reinhard Max <[email protected]>
+
+- bsc#1154849, CVE-2019-14834, dnsmasq-CVE-2019-14834.patch:
+  memory leak in the create_helper() function in /src/helper.c
+- bsc#1156543: include linux/sockios.h to get SIOCGSTAMP
+  (dnsmasq-siocgstamp.patch).
+- bsc#1138743: remove cache size limit (dnsmasq-cache-size.patch).
+- bsc#1152539: include config files from /etc/dnsmasq.d/*.conf .
+- bsc#1076958, CVE-2017-15107, dnsmasq-CVE-2017-15107.patch:
+  A vulnerability in DNSSEC implementation of Dnsmasq was found.
+  Processing of wildcard synthesized NSEC records may result in
+  improper validation for non-existance in some implementations of
+  DNSSEC. While synthesis of NSEC records is allowed by RFC4592,
+  the synthesized owner names should not be used in the NSEC
+  processing.
+- Package contrib/lease-tools/dhcp_release6.
+
+-------------------------------------------------------------------

New:
----
  dnsmasq-CVE-2017-15107.patch
  dnsmasq-CVE-2019-14834.patch
  dnsmasq-cache-size.patch
  dnsmasq-siocgstamp.patch

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ dnsmasq.spec ++++++
--- /var/tmp/diff_new_pack.ysZA8C/_old  2020-03-21 16:42:43.129374415 +0100
+++ /var/tmp/diff_new_pack.ysZA8C/_new  2020-03-21 16:42:43.129374415 +0100
@@ -35,6 +35,10 @@
 Source7:        SuSEFirewall.dnsmasq-dns
 Source8:        %{name}-rpmlintrc
 Patch0:         dnsmasq-groups.patch
+Patch1:         dnsmasq-CVE-2017-15107.patch
+Patch2:         dnsmasq-cache-size.patch
+Patch3:         dnsmasq-siocgstamp.patch
+Patch4:         dnsmasq-CVE-2019-14834.patch
 BuildRoot:      %{_tmppath}/%{name}-%{version}-build
 BuildRequires:  dbus-1-devel
 BuildRequires:  dos2unix
@@ -69,6 +73,10 @@
 %prep
 %setup -q
 %patch0
+%patch1
+%patch2
+%patch3
+%patch4
 
 # Remove the executable bit from python example files to
 # avoid unwanted automatic dependencies
@@ -95,8 +103,9 @@
           s|CHGRP "dip"|CHGRP "nogroup"|' \
        src/config.h
 
-# Fix trust-anchor.conf location
+# Fix trust-anchor.conf location and include /etc/dnsmasq.d/*.conf by default
 sed -i -e '/trust-anchors.conf/c\#conf-file=/etc/dnsmasq.d/trust-anchors.conf' 
\
+       -e '/conf-dir=.*conf/s/^\#//' \
        dnsmasq.conf.example
 
 %build
@@ -107,7 +116,6 @@
 # same flags for make and make install, else everything gets recompiled
 %define _copts   "-DHAVE_DBUS -DHAVE_CONNTRACK -DHAVE_IDN -DHAVE_DNSSEC 
-DHAVE_LUASCRIPT"
 make %{?_smp_mflags} AWK=gawk all-i18n CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS" 
COPTS=%{_copts}
-make -C contrib/lease-tools %{?_smp_mflags}
 
 %pre
 if ! /usr/bin/getent group tftp >/dev/null; then
@@ -159,11 +167,14 @@
 
 # utils subpackage
 mkdir -p $RPM_BUILD_ROOT%{_bindir} $RPM_BUILD_ROOT%{_mandir}/man1
+make -C contrib/lease-tools %{?_smp_mflags}
 install -m 755 contrib/lease-tools/dhcp_release 
${RPM_BUILD_ROOT}%{_bindir}/dhcp_release
 install -m 644 contrib/lease-tools/dhcp_release.1 
${RPM_BUILD_ROOT}%{_mandir}/man1/dhcp_release.1
+install -m 755 contrib/lease-tools/dhcp_release6 
%{buildroot}/%{_bindir}/dhcp_release6
+install -m 644 contrib/lease-tools/dhcp_release6.1 
%{buildroot}/%{_mandir}/man1/dhcp_release6.1
 install -m 755 contrib/lease-tools/dhcp_lease_time 
${RPM_BUILD_ROOT}%{_bindir}/dhcp_lease_time
 install -m 644 contrib/lease-tools/dhcp_lease_time.1 
${RPM_BUILD_ROOT}%{_mandir}/man1/dhcp_lease_time.1
-rm contrib/lease-tools/{dhcp_release,dhcp_lease_time}
+make -C contrib/lease-tools clean
 rm -rf contrib/Suse
 rm -rf contrib/Solaris10
 rm -rf contrib/dnsmasq_MacOSX-pre10.4


++++++ dnsmasq-CVE-2017-15107.patch ++++++
--- src/dnssec.c.orig
+++ src/dnssec.c
@@ -424,15 +424,17 @@ static void from_wire(char *name)
 static int count_labels(char *name)
 {
   int i;
-
+  char *p;
+  
   if (*name == 0)
     return 0;
 
-  for (i = 0; *name; name++)
-    if (*name == '.')
+  for (p = name, i = 0; *p; p++)
+    if (*p == '.')
       i++;
 
-  return i+1;
+  /* Don't count empty first label. */
+  return *name == '.' ? i : i+1;
 }
 
 /* Implement RFC1982 wrapped compare for 32-bit numbers */
@@ -1405,8 +1407,8 @@ static int hostname_cmp(const char *a, c
     }
 }
 
-static int prove_non_existence_nsec(struct dns_header *header, size_t plen, 
unsigned char **nsecs, int nsec_count,
-                                   char *workspace1, char *workspace2, char 
*name, int type, int *nons)
+static int prove_non_existence_nsec(struct dns_header *header, size_t plen, 
unsigned char **nsecs, unsigned char **labels, int nsec_count,
+                                   char *workspace1_in, char *workspace2, char 
*name, int type, int *nons)
 {
   int i, rc, rdlen;
   unsigned char *p, *psave;
@@ -1419,6 +1421,9 @@ static int prove_non_existence_nsec(stru
   /* Find NSEC record that proves name doesn't exist */
   for (i = 0; i < nsec_count; i++)
     {
+      char *workspace1 = workspace1_in;
+      int sig_labels, name_labels;
+
       p = nsecs[i];
       if (!extract_name(header, plen, &p, workspace1, 1, 10))
        return 0;
@@ -1427,7 +1432,27 @@ static int prove_non_existence_nsec(stru
       psave = p;
       if (!extract_name(header, plen, &p, workspace2, 1, 10))
        return 0;
-      
+
+      /* If NSEC comes from wildcard expansion, use original wildcard
+        as name for computation. */
+      sig_labels = *labels[i];
+      name_labels = count_labels(workspace1);
+
+      if (sig_labels < name_labels)
+       {
+         int k;
+         for (k = name_labels - sig_labels; k != 0; k--)
+           {
+             while (*workspace1 != '.' && *workspace1 != 0)
+               workspace1++;
+             if (k != 1 && *workspace1 == '.')
+               workspace1++;
+           }
+         
+         workspace1--;
+         *workspace1 = '*';
+       }
+         
       rc = hostname_cmp(workspace1, name);
       
       if (rc == 0)
@@ -1825,24 +1850,26 @@ static int prove_non_existence_nsec3(str
 
 static int prove_non_existence(struct dns_header *header, size_t plen, char 
*keyname, char *name, int qtype, int qclass, char *wildname, int *nons)
 {
-  static unsigned char **nsecset = NULL;
-  static int nsecset_sz = 0;
+  static unsigned char **nsecset = NULL, **rrsig_labels = NULL;
+  static int nsecset_sz = 0, rrsig_labels_sz = 0;
   
   int type_found = 0;
-  unsigned char *p = skip_questions(header, plen);
+  unsigned char *auth_start, *p = skip_questions(header, plen);
   int type, class, rdlen, i, nsecs_found;
   
   /* Move to NS section */
   if (!p || !(p = skip_section(p, ntohs(header->ancount), header, plen)))
     return 0;
+
+  auth_start = p;
   
   for (nsecs_found = 0, i = ntohs(header->nscount); i != 0; i--)
     {
       unsigned char *pstart = p;
       
-      if (!(p = skip_name(p, header, plen, 10)))
+      if (!extract_name(header, plen, &p, daemon->workspacename, 1, 10))
        return 0;
-      
+         
       GETSHORT(type, p); 
       GETSHORT(class, p);
       p += 4; /* TTL */
@@ -1859,7 +1886,69 @@ static int prove_non_existence(struct dn
          if (!expand_workspace(&nsecset, &nsecset_sz, nsecs_found))
            return 0; 
          
-         nsecset[nsecs_found++] = pstart;
+         if (type == T_NSEC)
+           {
+             /* If we're looking for NSECs, find the corresponding SIGs, to 
+                extract the labels value, which we need in case the NSECs
+                are the result of wildcard expansion.
+                Note that the NSEC may not have been validated yet
+                so if there are multiple SIGs, make sure the label value
+                is the same in all, to avoid be duped by a rogue one.
+                If there are no SIGs, that's an error */
+             unsigned char *p1 = auth_start;
+             int res, j, rdlen1, type1, class1;
+             
+             if (!expand_workspace(&rrsig_labels, &rrsig_labels_sz, 
nsecs_found))
+               return 0;
+             
+             rrsig_labels[nsecs_found] = NULL;
+             
+             for (j = ntohs(header->nscount); j != 0; j--)
+               {
+                 if (!(res = extract_name(header, plen, &p1, 
daemon->workspacename, 0, 10)))
+                   return 0;
+
+                  GETSHORT(type1, p1); 
+                  GETSHORT(class1, p1);
+                  p1 += 4; /* TTL */
+                  GETSHORT(rdlen1, p1);
+
+                  if (!CHECK_LEN(header, p1, plen, rdlen1))
+                    return 0;
+                  
+                  if (res == 1 && class1 == qclass && type1 == T_RRSIG)
+                    {
+                      int type_covered;
+                      unsigned char *psav = p1;
+                      
+                      if (rdlen < 18)
+                        return 0; /* bad packet */
+
+                      GETSHORT(type_covered, p1);
+
+                      if (type_covered == T_NSEC)
+                        {
+                          p1++; /* algo */
+                          
+                          /* labels field must be the same in every SIG we 
find. */
+                          if (!rrsig_labels[nsecs_found])
+                            rrsig_labels[nsecs_found] = p1;
+                          else if (*rrsig_labels[nsecs_found] != *p1) /* algo 
*/
+                            return 0;
+                          }
+                      p1 = psav;
+                    }
+                  
+                  if (!ADD_RDLEN(header, p1, plen, rdlen1))
+                    return 0;
+               }
+
+             /* Must have found at least one sig. */
+             if (!rrsig_labels[nsecs_found])
+               return 0;
+           }
+
+         nsecset[nsecs_found++] = pstart;   
        }
       
       if (!ADD_RDLEN(header, p, plen, rdlen))
@@ -1867,7 +1956,7 @@ static int prove_non_existence(struct dn
     }
   
   if (type_found == T_NSEC)
-    return prove_non_existence_nsec(header, plen, nsecset, nsecs_found, 
daemon->workspacename, keyname, name, qtype, nons);
+    return prove_non_existence_nsec(header, plen, nsecset, rrsig_labels, 
nsecs_found, daemon->workspacename, keyname, name, qtype, nons);
   else if (type_found == T_NSEC3)
     return prove_non_existence_nsec3(header, plen, nsecset, nsecs_found, 
daemon->workspacename, keyname, name, qtype, wildname, nons);
   else
++++++ dnsmasq-CVE-2019-14834.patch ++++++
X-Git-Url: 
http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=blobdiff_plain;f=src%2Fhelper.c;h=c392eeced3e73762d3ea6a2f9fa27ab5ae389241;hp=33ba120ab39e3788719a18796b5b58338972e1e8;hb=69bc94779c2f035a9fffdb5327a54c3aeca73ed5;hpb=3052ce208acf602f0163166dcefb7330d537cedb

--- src/helper.c.orig
+++ src/helper.c
@@ -82,7 +82,8 @@ int create_helper(int event_fd, int err_
   pid_t pid;
   int i, pipefd[2];
   struct sigaction sigact;
-
+  unsigned char *alloc_buff = NULL;
+  
   /* create the pipe through which the main program sends us commands,
      then fork our process. */
   if (pipe(pipefd) == -1 || !fix_fd(pipefd[1]) || (pid = fork()) == -1)
@@ -188,11 +189,16 @@ int create_helper(int event_fd, int err_
       struct script_data data;
       char *p, *action_str, *hostname = NULL, *domain = NULL;
       unsigned char *buf = (unsigned char *)daemon->namebuff;
-      unsigned char *end, *extradata, *alloc_buff = NULL;
+      unsigned char *end, *extradata;
       int is6, err = 0;
       int pipeout[2];
 
-      free(alloc_buff);
+      /* Free rarely-allocated memory from previous iteration. */
+      if (alloc_buff)
+       {
+         free(alloc_buff);
+         alloc_buff = NULL;
+       }
       
       /* we read zero bytes when pipe closed: this is our signal to exit */ 
       if (!read_write(pipefd[0], (unsigned char *)&data, sizeof(data), 1))
++++++ dnsmasq-cache-size.patch ++++++
--- src/dnsmasq.c.orig
+++ src/dnsmasq.c
@@ -717,7 +717,11 @@ int main (int argc, char **argv)
   else 
     {
       if (daemon->cachesize != 0)
-       my_syslog(LOG_INFO, _("started, version %s cachesize %d"), VERSION, 
daemon->cachesize);
+       {
+         my_syslog(LOG_INFO, _("started, version %s cachesize %d"), VERSION, 
daemon->cachesize);
+         if (daemon->cachesize > 10000)
+           my_syslog(LOG_WARNING, _("cache size greater than 10000 may cause 
performance issues, and is unlikely to be useful."));
+       }
       else
        my_syslog(LOG_INFO, _("started, version %s cache disabled"), VERSION);
 
--- src/option.c.orig
+++ src/option.c
@@ -2579,8 +2579,6 @@ static int one_opt(int option, char *arg
            
            if (size < 0)
              size = 0;
-           else if (size > 10000)
-             size = 10000;
            
            daemon->cachesize = size;
          }
++++++ dnsmasq-siocgstamp.patch ++++++
From: Jiri Slaby <[email protected]>
Date: Wed, 10 Jul 2019 08:19:06 +0200
Subject: fix build after y2038 changes in glibc
Patch-mainline: submitted on 2019/07/10

SIOCGSTAMP is defined in linux/sockios.h, not asm/sockios.h now.

Signed-off-by: Jiri Slaby <[email protected]>
---
 src/dnsmasq.h | 1 +
 1 file changed, 1 insertion(+)

--- src/dnsmasq.h.orig
+++ src/dnsmasq.h
@@ -128,6 +128,7 @@ typedef unsigned long long u64;
 #endif
 
 #if defined(HAVE_LINUX_NETWORK)
+#include <linux/sockios.h>
 #include <linux/capability.h>
 /* There doesn't seem to be a universally-available 
    userspace header for these. */


Reply via email to