Hello community, here is the log from the commit of package dnsmasq for openSUSE:Leap:15.2 checked in at 2020-03-21 16:42:41 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Leap:15.2/dnsmasq (Old) and /work/SRC/openSUSE:Leap:15.2/.dnsmasq.new.3160 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "dnsmasq" Sat Mar 21 16:42:41 2020 rev:20 rq:754915 version:2.78 Changes: -------- --- /work/SRC/openSUSE:Leap:15.2/dnsmasq/dnsmasq.changes 2020-01-15 14:52:36.317495357 +0100 +++ /work/SRC/openSUSE:Leap:15.2/.dnsmasq.new.3160/dnsmasq.changes 2020-03-21 16:42:42.465373734 +0100 @@ -1,0 +2,18 @@ +Wed Nov 13 10:23:27 UTC 2019 - Reinhard Max <[email protected]> + +- bsc#1154849, CVE-2019-14834, dnsmasq-CVE-2019-14834.patch: + memory leak in the create_helper() function in /src/helper.c +- bsc#1156543: include linux/sockios.h to get SIOCGSTAMP + (dnsmasq-siocgstamp.patch). +- bsc#1138743: remove cache size limit (dnsmasq-cache-size.patch). +- bsc#1152539: include config files from /etc/dnsmasq.d/*.conf . +- bsc#1076958, CVE-2017-15107, dnsmasq-CVE-2017-15107.patch: + A vulnerability in DNSSEC implementation of Dnsmasq was found. + Processing of wildcard synthesized NSEC records may result in + improper validation for non-existance in some implementations of + DNSSEC. While synthesis of NSEC records is allowed by RFC4592, + the synthesized owner names should not be used in the NSEC + processing. +- Package contrib/lease-tools/dhcp_release6. + +------------------------------------------------------------------- New: ---- dnsmasq-CVE-2017-15107.patch dnsmasq-CVE-2019-14834.patch dnsmasq-cache-size.patch dnsmasq-siocgstamp.patch ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ dnsmasq.spec ++++++ --- /var/tmp/diff_new_pack.ysZA8C/_old 2020-03-21 16:42:43.129374415 +0100 +++ /var/tmp/diff_new_pack.ysZA8C/_new 2020-03-21 16:42:43.129374415 +0100 @@ -35,6 +35,10 @@ Source7: SuSEFirewall.dnsmasq-dns Source8: %{name}-rpmlintrc Patch0: dnsmasq-groups.patch +Patch1: dnsmasq-CVE-2017-15107.patch +Patch2: dnsmasq-cache-size.patch +Patch3: dnsmasq-siocgstamp.patch +Patch4: dnsmasq-CVE-2019-14834.patch BuildRoot: %{_tmppath}/%{name}-%{version}-build BuildRequires: dbus-1-devel BuildRequires: dos2unix @@ -69,6 +73,10 @@ %prep %setup -q %patch0 +%patch1 +%patch2 +%patch3 +%patch4 # Remove the executable bit from python example files to # avoid unwanted automatic dependencies @@ -95,8 +103,9 @@ s|CHGRP "dip"|CHGRP "nogroup"|' \ src/config.h -# Fix trust-anchor.conf location +# Fix trust-anchor.conf location and include /etc/dnsmasq.d/*.conf by default sed -i -e '/trust-anchors.conf/c\#conf-file=/etc/dnsmasq.d/trust-anchors.conf' \ + -e '/conf-dir=.*conf/s/^\#//' \ dnsmasq.conf.example %build @@ -107,7 +116,6 @@ # same flags for make and make install, else everything gets recompiled %define _copts "-DHAVE_DBUS -DHAVE_CONNTRACK -DHAVE_IDN -DHAVE_DNSSEC -DHAVE_LUASCRIPT" make %{?_smp_mflags} AWK=gawk all-i18n CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS" COPTS=%{_copts} -make -C contrib/lease-tools %{?_smp_mflags} %pre if ! /usr/bin/getent group tftp >/dev/null; then @@ -159,11 +167,14 @@ # utils subpackage mkdir -p $RPM_BUILD_ROOT%{_bindir} $RPM_BUILD_ROOT%{_mandir}/man1 +make -C contrib/lease-tools %{?_smp_mflags} install -m 755 contrib/lease-tools/dhcp_release ${RPM_BUILD_ROOT}%{_bindir}/dhcp_release install -m 644 contrib/lease-tools/dhcp_release.1 ${RPM_BUILD_ROOT}%{_mandir}/man1/dhcp_release.1 +install -m 755 contrib/lease-tools/dhcp_release6 %{buildroot}/%{_bindir}/dhcp_release6 +install -m 644 contrib/lease-tools/dhcp_release6.1 %{buildroot}/%{_mandir}/man1/dhcp_release6.1 install -m 755 contrib/lease-tools/dhcp_lease_time ${RPM_BUILD_ROOT}%{_bindir}/dhcp_lease_time install -m 644 contrib/lease-tools/dhcp_lease_time.1 ${RPM_BUILD_ROOT}%{_mandir}/man1/dhcp_lease_time.1 -rm contrib/lease-tools/{dhcp_release,dhcp_lease_time} +make -C contrib/lease-tools clean rm -rf contrib/Suse rm -rf contrib/Solaris10 rm -rf contrib/dnsmasq_MacOSX-pre10.4 ++++++ dnsmasq-CVE-2017-15107.patch ++++++ --- src/dnssec.c.orig +++ src/dnssec.c @@ -424,15 +424,17 @@ static void from_wire(char *name) static int count_labels(char *name) { int i; - + char *p; + if (*name == 0) return 0; - for (i = 0; *name; name++) - if (*name == '.') + for (p = name, i = 0; *p; p++) + if (*p == '.') i++; - return i+1; + /* Don't count empty first label. */ + return *name == '.' ? i : i+1; } /* Implement RFC1982 wrapped compare for 32-bit numbers */ @@ -1405,8 +1407,8 @@ static int hostname_cmp(const char *a, c } } -static int prove_non_existence_nsec(struct dns_header *header, size_t plen, unsigned char **nsecs, int nsec_count, - char *workspace1, char *workspace2, char *name, int type, int *nons) +static int prove_non_existence_nsec(struct dns_header *header, size_t plen, unsigned char **nsecs, unsigned char **labels, int nsec_count, + char *workspace1_in, char *workspace2, char *name, int type, int *nons) { int i, rc, rdlen; unsigned char *p, *psave; @@ -1419,6 +1421,9 @@ static int prove_non_existence_nsec(stru /* Find NSEC record that proves name doesn't exist */ for (i = 0; i < nsec_count; i++) { + char *workspace1 = workspace1_in; + int sig_labels, name_labels; + p = nsecs[i]; if (!extract_name(header, plen, &p, workspace1, 1, 10)) return 0; @@ -1427,7 +1432,27 @@ static int prove_non_existence_nsec(stru psave = p; if (!extract_name(header, plen, &p, workspace2, 1, 10)) return 0; - + + /* If NSEC comes from wildcard expansion, use original wildcard + as name for computation. */ + sig_labels = *labels[i]; + name_labels = count_labels(workspace1); + + if (sig_labels < name_labels) + { + int k; + for (k = name_labels - sig_labels; k != 0; k--) + { + while (*workspace1 != '.' && *workspace1 != 0) + workspace1++; + if (k != 1 && *workspace1 == '.') + workspace1++; + } + + workspace1--; + *workspace1 = '*'; + } + rc = hostname_cmp(workspace1, name); if (rc == 0) @@ -1825,24 +1850,26 @@ static int prove_non_existence_nsec3(str static int prove_non_existence(struct dns_header *header, size_t plen, char *keyname, char *name, int qtype, int qclass, char *wildname, int *nons) { - static unsigned char **nsecset = NULL; - static int nsecset_sz = 0; + static unsigned char **nsecset = NULL, **rrsig_labels = NULL; + static int nsecset_sz = 0, rrsig_labels_sz = 0; int type_found = 0; - unsigned char *p = skip_questions(header, plen); + unsigned char *auth_start, *p = skip_questions(header, plen); int type, class, rdlen, i, nsecs_found; /* Move to NS section */ if (!p || !(p = skip_section(p, ntohs(header->ancount), header, plen))) return 0; + + auth_start = p; for (nsecs_found = 0, i = ntohs(header->nscount); i != 0; i--) { unsigned char *pstart = p; - if (!(p = skip_name(p, header, plen, 10))) + if (!extract_name(header, plen, &p, daemon->workspacename, 1, 10)) return 0; - + GETSHORT(type, p); GETSHORT(class, p); p += 4; /* TTL */ @@ -1859,7 +1886,69 @@ static int prove_non_existence(struct dn if (!expand_workspace(&nsecset, &nsecset_sz, nsecs_found)) return 0; - nsecset[nsecs_found++] = pstart; + if (type == T_NSEC) + { + /* If we're looking for NSECs, find the corresponding SIGs, to + extract the labels value, which we need in case the NSECs + are the result of wildcard expansion. + Note that the NSEC may not have been validated yet + so if there are multiple SIGs, make sure the label value + is the same in all, to avoid be duped by a rogue one. + If there are no SIGs, that's an error */ + unsigned char *p1 = auth_start; + int res, j, rdlen1, type1, class1; + + if (!expand_workspace(&rrsig_labels, &rrsig_labels_sz, nsecs_found)) + return 0; + + rrsig_labels[nsecs_found] = NULL; + + for (j = ntohs(header->nscount); j != 0; j--) + { + if (!(res = extract_name(header, plen, &p1, daemon->workspacename, 0, 10))) + return 0; + + GETSHORT(type1, p1); + GETSHORT(class1, p1); + p1 += 4; /* TTL */ + GETSHORT(rdlen1, p1); + + if (!CHECK_LEN(header, p1, plen, rdlen1)) + return 0; + + if (res == 1 && class1 == qclass && type1 == T_RRSIG) + { + int type_covered; + unsigned char *psav = p1; + + if (rdlen < 18) + return 0; /* bad packet */ + + GETSHORT(type_covered, p1); + + if (type_covered == T_NSEC) + { + p1++; /* algo */ + + /* labels field must be the same in every SIG we find. */ + if (!rrsig_labels[nsecs_found]) + rrsig_labels[nsecs_found] = p1; + else if (*rrsig_labels[nsecs_found] != *p1) /* algo */ + return 0; + } + p1 = psav; + } + + if (!ADD_RDLEN(header, p1, plen, rdlen1)) + return 0; + } + + /* Must have found at least one sig. */ + if (!rrsig_labels[nsecs_found]) + return 0; + } + + nsecset[nsecs_found++] = pstart; } if (!ADD_RDLEN(header, p, plen, rdlen)) @@ -1867,7 +1956,7 @@ static int prove_non_existence(struct dn } if (type_found == T_NSEC) - return prove_non_existence_nsec(header, plen, nsecset, nsecs_found, daemon->workspacename, keyname, name, qtype, nons); + return prove_non_existence_nsec(header, plen, nsecset, rrsig_labels, nsecs_found, daemon->workspacename, keyname, name, qtype, nons); else if (type_found == T_NSEC3) return prove_non_existence_nsec3(header, plen, nsecset, nsecs_found, daemon->workspacename, keyname, name, qtype, wildname, nons); else ++++++ dnsmasq-CVE-2019-14834.patch ++++++ X-Git-Url: http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=blobdiff_plain;f=src%2Fhelper.c;h=c392eeced3e73762d3ea6a2f9fa27ab5ae389241;hp=33ba120ab39e3788719a18796b5b58338972e1e8;hb=69bc94779c2f035a9fffdb5327a54c3aeca73ed5;hpb=3052ce208acf602f0163166dcefb7330d537cedb --- src/helper.c.orig +++ src/helper.c @@ -82,7 +82,8 @@ int create_helper(int event_fd, int err_ pid_t pid; int i, pipefd[2]; struct sigaction sigact; - + unsigned char *alloc_buff = NULL; + /* create the pipe through which the main program sends us commands, then fork our process. */ if (pipe(pipefd) == -1 || !fix_fd(pipefd[1]) || (pid = fork()) == -1) @@ -188,11 +189,16 @@ int create_helper(int event_fd, int err_ struct script_data data; char *p, *action_str, *hostname = NULL, *domain = NULL; unsigned char *buf = (unsigned char *)daemon->namebuff; - unsigned char *end, *extradata, *alloc_buff = NULL; + unsigned char *end, *extradata; int is6, err = 0; int pipeout[2]; - free(alloc_buff); + /* Free rarely-allocated memory from previous iteration. */ + if (alloc_buff) + { + free(alloc_buff); + alloc_buff = NULL; + } /* we read zero bytes when pipe closed: this is our signal to exit */ if (!read_write(pipefd[0], (unsigned char *)&data, sizeof(data), 1)) ++++++ dnsmasq-cache-size.patch ++++++ --- src/dnsmasq.c.orig +++ src/dnsmasq.c @@ -717,7 +717,11 @@ int main (int argc, char **argv) else { if (daemon->cachesize != 0) - my_syslog(LOG_INFO, _("started, version %s cachesize %d"), VERSION, daemon->cachesize); + { + my_syslog(LOG_INFO, _("started, version %s cachesize %d"), VERSION, daemon->cachesize); + if (daemon->cachesize > 10000) + my_syslog(LOG_WARNING, _("cache size greater than 10000 may cause performance issues, and is unlikely to be useful.")); + } else my_syslog(LOG_INFO, _("started, version %s cache disabled"), VERSION); --- src/option.c.orig +++ src/option.c @@ -2579,8 +2579,6 @@ static int one_opt(int option, char *arg if (size < 0) size = 0; - else if (size > 10000) - size = 10000; daemon->cachesize = size; } ++++++ dnsmasq-siocgstamp.patch ++++++ From: Jiri Slaby <[email protected]> Date: Wed, 10 Jul 2019 08:19:06 +0200 Subject: fix build after y2038 changes in glibc Patch-mainline: submitted on 2019/07/10 SIOCGSTAMP is defined in linux/sockios.h, not asm/sockios.h now. Signed-off-by: Jiri Slaby <[email protected]> --- src/dnsmasq.h | 1 + 1 file changed, 1 insertion(+) --- src/dnsmasq.h.orig +++ src/dnsmasq.h @@ -128,6 +128,7 @@ typedef unsigned long long u64; #endif #if defined(HAVE_LINUX_NETWORK) +#include <linux/sockios.h> #include <linux/capability.h> /* There doesn't seem to be a universally-available userspace header for these. */
