From patchwork Thu Sep 10 23:09:00 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97892 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0775AC88E41 for ; Thu, 10 Sep 2026 23:09:47 +0000 (UTC) Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27823.1789081784514093267 for ; Thu, 10 Sep 2026 16:09:44 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=OXf0Xpuc; spf=pass (domain: gmail.com, ip: 209.85.216.50, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-39682983a0fso329506a91.3 for ; Thu, 10 Sep 2026 16:09:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081784; x=1789686584; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=KUHEhkGWcUieOKQ9U3LGTnPgeil3Rq+GOFgBFI6zTyA=; b=OXf0XpucahIKUWuNqO/JnQRlvSX5VB46bOY1Hz+27JTmo21Qt3kkTh+/lmLda2MkzT h2ryncPPhpSpXHbH0lfaAns5WGSTtWShsdtRWGSVQgo56H3Mq8/eq4l93dqlsJI3iz2c k8GCH111RB4Y6Gtk1yWAlm1Hty5CbuocvrqO0XgMrOYSk+cwNDpfRwzDOKB4e1R15+bE CW5zVkyjVHSecFCdSXX03v4zakfpKX2pj4Wa72u+lrIFg5HYC2UqNJmKlb7tUQKlGyWx eJIfQXua6Hj2iLL3gMKfqwhBEl0rRVgNJson7+Sn0SqgdUuJAa+CwlhMyMlfM5rkd6L6 N4oQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081784; x=1789686584; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KUHEhkGWcUieOKQ9U3LGTnPgeil3Rq+GOFgBFI6zTyA=; b=lTdUTJ7erCtGyiEGoID8C6sTkM6VO15PMgIZWRl4e2KAe8/fxrTiV93nAPsgabOe4H wSazyiFOgUkjdNOdJauT6vHRpwgem3pBA5B2p5IQOr7tZHOECx8s2cj3y7xvL8M13Lpi dOq26aU9T3KEARqU2wBEdQPUo7oQE+6j+usDWZfO0KNOIbS7ZsP7tccA6khZ6Gh06Wmi BETW6PYuE6q9+FD49o+bo9jSzqoPLrLu2y3OY2kAHDlHhq0F2x1hycDBAJqgdcIhqX2f UaSWRDnmwAMxvuqwtwxS0SX5orRkYCjQpfPLvgjkdtT/KOfd26fwXMuZMtLzj0+aGQt9 dhcg== X-Gm-Message-State: AFuF++lpufS3Zyp5P9Fk9LM9qASvr019hQIMxljZnXtbvIZjx2YmL/Ts zN2jN8P9dhjHLjPPYdLVITe3u4U2cgMnTynDXGFdVI2qSadwM+Q8BM3yPL8bDw== X-Gm-Gg: AYBFou0fH/ug2wbT66If//cRnk8MOiznJddQgyk3+jnCjwTM7ic1iUbdeGHU8xlQnDy 00TBwWALYmOMKIjtNl7xA5Q0dk/tDUgWJNlqt2y2CFGSeNYpPOlRU3MyY1Plrncfq8xK/q5K+aR FxFFbgVX160nXKA3I6m98exMG6CRl8cyrjBvsOH11rUjKHq0EvG59z2hKuh8ykVWU9l5FyliTmo TjrAl1PMCvy8LSrsh6opDxVlsBOfoybTnZy55rQzGYfuR6VOtwE9GlLGmdqdHi8jiEAaxmsHIhn EMu3P865JRqa2NC2oG1Xo9x3fDd+AQnJ0ll2rrhbQFqdIhFBVBct2qFRYCMOhlq21ieKA6G+Y65 ZW3LRe6FQ0h6bfgsG4DolEBKakcGhKHJPosn/NDI79Wz3IB2iYYJO2b365/zIt+FU2aacYd0b9E cFnozX6gS00c9wdvlNSPUHXKd4a1uYQeL1wQCehuCG2pQhKK9ZwHU73BXMKcVVxK9+RLq7BIrNf 5wJlsEOgDB6HULvqjO55zo+XB6XbBNNag== X-Received: by 2002:a17:90b:1b05:b0:38f:5869:387b with SMTP id 98e67ed59e1d1-39d9bd9515amr1679208a91.9.1789081783841; Thu, 10 Sep 2026 16:09:43 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.09.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:09:43 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-oe][wrynose][PATCH 1/32] zabbix: ignore multiple CVEs Date: Fri, 11 Sep 2026 11:09:00 +1200 Message-ID: <20260910230932.173913-1-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:09:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129919 From: Ankur Tyagi CVE-2026-23922 https://support.zabbix.com/browse/ZBX-28067 https://nvd.nist.gov/vuln/detail/cve-2026-23922 CVE-2026-23924 https://support.zabbix.com/browse/ZBX-27642 https://nvd.nist.gov/vuln/detail/cve-2026-23924 https://github.com/zabbix/zabbix/blob/7.4.14/ChangeLog#L1856 CVE-2026-23926 https://support.zabbix.com/browse/ZBX-27758 https://nvd.nist.gov/vuln/detail/cve-2026-23926 https://github.com/zabbix/zabbix/blob/7.4.14/ChangeLog#L1787 CVE-2026-23927 https://support.zabbix.com/browse/ZBX-27759 https://nvd.nist.gov/vuln/detail/cve-2026-23927 https://github.com/zabbix/zabbix/blob/7.4.14/ChangeLog#L1785 CVE-2026-23928 https://support.zabbix.com/browse/ZBX-27760 https://nvd.nist.gov/vuln/detail/cve-2026-23928 https://github.com/zabbix/zabbix/blob/7.4.14/ChangeLog#L1786 CVE-2026-23931 https://support.zabbix.com/browse/ZBX-28070 https://nvd.nist.gov/vuln/detail/cve-2026-23931 CVE-2026-23933 https://support.zabbix.com/browse/ZBX-28071 https://nvd.nist.gov/vuln/detail/cve-2026-23933 CVE-2026-23934 https://support.zabbix.com/browse/ZBX-28072 https://nvd.nist.gov/vuln/detail/cve-2026-23934 Signed-off-by: Ankur Tyagi --- meta-oe/recipes-connectivity/zabbix/zabbix_7.0.24.bb | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/meta-oe/recipes-connectivity/zabbix/zabbix_7.0.24.bb b/meta-oe/recipes-connectivity/zabbix/zabbix_7.0.24.bb index 1ec159cdee..7dcb69b070 100644 --- a/meta-oe/recipes-connectivity/zabbix/zabbix_7.0.24.bb +++ b/meta-oe/recipes-connectivity/zabbix/zabbix_7.0.24.bb @@ -82,3 +82,11 @@ CVE_STATUS[CVE-2026-23919] = "fixed-version: fixed since 7.0.19" CVE_STATUS[CVE-2026-23920] = "fixed-version: fixed since 7.0.22" CVE_STATUS[CVE-2026-23921] = "fixed-version: fixed since 7.0.22" CVE_STATUS[CVE-2026-23923] = "cpe-incorrect: 7.0 versions don't have the vulnerable code" +CVE_STATUS[CVE-2026-23922] = "cpe-incorrect: Only affects 7.4.x" +CVE_STATUS[CVE-2026-23924] = "fixed-version: fixed since 7.0.23" +CVE_STATUS[CVE-2026-23926] = "fixed-version: fixed in 7.0.24" +CVE_STATUS[CVE-2026-23927] = "fixed-version: fixed in 7.0.24" +CVE_STATUS[CVE-2026-23928] = "fixed-version: fixed in 7.0.24" +CVE_STATUS[CVE-2026-23931] = "cpe-incorrect: Only affects 7.4.x" +CVE_STATUS[CVE-2026-23933] = "cpe-incorrect: Only affects 7.4.x" +CVE_STATUS[CVE-2026-23934] = "cpe-incorrect: Only affects 7.4.x" From patchwork Thu Sep 10 23:09:01 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97894 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id D8421C88E41 for ; Thu, 10 Sep 2026 23:09:56 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27825.1789081787888692604 for ; Thu, 10 Sep 2026 16:09:47 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=c/m8+YEQ; spf=pass (domain: gmail.com, ip: 74.125.227.140, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj2-f12.google.com with SMTP id 98e67ed59e1d1-396ccafb74fso265441a91.3 for ; Thu, 10 Sep 2026 16:09:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081787; x=1789686587; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=FKFVlwQVYD6zrfBakG8yUJYdGoCWSd6q6BW/yxHEEhs=; b=c/m8+YEQ6UkpV2S4pqBVnidWoxUgiEeJ1sFAbW2v6vIKmRE6aUPZXdDOQtm1qctPha BIti8GaoxRuIo+HMzHZ0CXQZRQe3h2bkOMU6jMHJitHo6UejdELF1VX+9nZc74vaE1kE Rqgqq81m37lWvuMvNuza50XuDEPN8zePdBh7nQHzJv2kvIMvSNbt1/vVFL64Fu4fFmWc B8EW1GkIiRHpazYib+uRqKRl7ccVMhBBZX6ULeUci5WxxwV7sVMsRxKQKhKD58uowr5g 0mYoeCVSV01ldxJCFE05ARtzoHJCxkXLfj71Equ6SqYHjHDHJP5HpNuiKotRSzZL5OlS +Mpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081787; x=1789686587; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=FKFVlwQVYD6zrfBakG8yUJYdGoCWSd6q6BW/yxHEEhs=; b=abKub22cI0C1JoCMPHGiYrXRDOUM9ycahkCwYYcCP7fraapmH4TeCPAC2nan0ntYn5 uRSwu80aqrtbXDADe83jtnlsRoqvB6wpCVoJioLy33Z0+kCvfmOlHkbPmuMVMK6AHmmq aQsqHm3FqzFOiE6SRHVjGmREHbTwz0Jh32fM6UNj+JzFabXNSNJzCZgRuYmkdYaiQP96 8H439sSyj3yjjrKkLQsh+4hjOJnNJwFtToda+WAA/HAyqv0JBrXLq1Lxbhknb3TkjUMm 7/M1X18NfeVWeDzajUyNch4xawnoodNI2OV7ohgXOOM5X8URg7vESYfZxxtFTqkYwr53 NWMQ== X-Gm-Message-State: AFuF++nxffE5rRNIyZ72RhQA4pBGh1qYI1YZeDF6muM3kqiRmPkUPdf4 V4gWL9UVouxCPYENxLkRg9Wnb3hzNMPGTMe25qYSGGhLxXbLuiVtab4lbmkoGw== X-Gm-Gg: AYBFou1t6RxsA4asINCVb1gn+Yp3fK1lsvWHb9qJb3WxD+FAqprRF98QWKrcsjED/dA xs/Xj8WxF0XHtF7PfKXA63K9WthOQvCPTq7JEL1ONIUJoMON/012xU6NJzkyFqLGsoovViCmMnq BoRFWk+n5lHv+9gARYumkLA8MZdnKguFaZp0K+aiTxRoeqcrLe8WuKGdGa8jSb/ssTUY/UnsVOw PZ8JhR4BaH6FhqqOMpgrolPu16wKVdD1vbSaFq+yA6Y5P2SwXk+BjuS4cYUvRqxvW/V6Vg4gAHn dHlHJVd/ptKfurztACdbR4jlIhN6eyKnUCtWLQQbTwC7hD7eMi696KIRYo12A/wT80gk4RXUt2k ifnJ7Blbw3S+zDk160x1IzH2ydbZ0Qb1Y3NJcmbZpJ/EPkNyAw/aXtdyiCd3bs5GdxgmxhGyp4D D4H3QyXMqKi3qb4pu8InmpRXARrwncic+b1yh7+Za/OTo/uCnxQ/YlhlyYjlH9/0EUz/S0/4mPQ 1evhubfq5NHdhwjWwdxoBE= X-Received: by 2002:a17:90a:d64e:b0:395:4de4:92be with SMTP id 98e67ed59e1d1-39d9c1db130mr1944870a91.13.1789081786997; Thu, 10 Sep 2026 16:09:46 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.09.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:09:46 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 2/32] unbound: patch CVE-2026-33278 Date: Fri, 11 Sep 2026 11:09:01 +1200 Message-ID: <20260910230932.173913-2-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:09:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129920 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-33278 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-33278.patch | 296 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 297 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-33278.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-33278.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-33278.patch new file mode 100644 index 0000000000..b42b613546 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-33278.patch @@ -0,0 +1,296 @@ +From f7633e132f79548d71c02ed66d55a82c23ea0a82 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:13:08 +0200 +Subject: [PATCH] - Fix CVE-2026-33278, Possible remote code execution during + DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the + report. + +(cherry picked from commit 6a31e470f80a6e5c559ebe7fd4cfc0582d3b6d0a) + +CVE: CVE-2026-33278 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/6a31e470f80a6e5c559ebe7fd4cfc0582d3b6d0a] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + services/cache/dns.c | 8 +++- + testdata/val_nsec3_iter_high.rpl | 18 ++++---- + testdata/val_nx_nsec3_collision.rpl | 31 +++++-------- + testdata/val_nx_nsec3_params.rpl | 22 +++++---- + validator/val_nsec3.c | 71 +++++++++++++++++++++++++++++ + 5 files changed, 111 insertions(+), 39 deletions(-) + +diff --git a/services/cache/dns.c b/services/cache/dns.c +index 351b3568c..8dae2ffcc 100644 +--- a/services/cache/dns.c ++++ b/services/cache/dns.c +@@ -675,10 +675,16 @@ struct dns_msg* + dns_msg_deepcopy_region(struct dns_msg* origin, struct regional* region) + { + size_t i; ++ struct ub_packed_rrset_key** saved_rrsets; + struct dns_msg* res = NULL; ++ size_t rep_alloc_size = sizeof(struct reply_info) ++ - sizeof(struct rrset_ref); /* this is the size of res->rep ++ allocated in gen_dns_msg() */ + res = gen_dns_msg(region, &origin->qinfo, origin->rep->rrset_count); + if(!res) return NULL; +- *res->rep = *origin->rep; ++ saved_rrsets = res->rep->rrsets; /* save rrsets alloc by gen_dns_msg */ ++ memcpy(res->rep, origin->rep, rep_alloc_size); ++ res->rep->rrsets = saved_rrsets; + if(origin->rep->reason_bogus_str) { + res->rep->reason_bogus_str = regional_strdup(region, + origin->rep->reason_bogus_str); +diff --git a/testdata/val_nsec3_iter_high.rpl b/testdata/val_nsec3_iter_high.rpl +index 2b78f0b7f..703092d89 100644 +--- a/testdata/val_nsec3_iter_high.rpl ++++ b/testdata/val_nsec3_iter_high.rpl +@@ -120,12 +120,12 @@ example.com. IN SOA ns.example.com. hostmaster.example.com. 2007090400 28800 720 + example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFCNGZ+/OfElYQMCZ77O9Lw9rhk7PAhUAmDcvTAst6Bq83qPq3r6c/Dm1nFc= ;{id = 2854} + + ; closest encloser, H(example.com). +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. NSEC3 1 1 8 - 6md8numosa4q9ugkffdo1bmm82t5j49s SOA NS MX DNSKEY RRSIG +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCz/LkFOFcaQzVnyySW9ZoVUnxh7gIUdxyS9vqVDzo8pGhFU+3YogN2ZRk= ;{id = 2854} ++b6fuorg741ufili49mg9j4328ig53sqg.example.com. NSEC3 1 1 123 aabb00123456bbccdd b6fuorg741ufili49mg9j4328ig53sqh SOA NS MX DNSKEY RRSIG ++b6fuorg741ufili49mg9j4328ig53sqg.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. AJlV5car66lq5f0ASx7W47A/OADkARAXzKt9ZLojXze+FWK9JjAX+eA= + +-; wildcard denial, H(*.example.com.) = 4f3cnt8cu22tngec382jj4gde4rb47ub +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. NSEC3 1 1 0 - 4f3cnt8cu22tngec382jj4gde4rb48ub A MX RRSIG +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MCwCFHS+i/OB/V/gYmS1eQTXieXIXGjsAhQQ0Ql7TW/hsUklrb0DfoyhVPG95Q== ;{id = 2854} ++; wildcard denial, H(*.example.com.) = k1a2vr9c269jummpru5d68qllbfmtdcb. ++k1a2vr9c269jummpru5d68qllbfmtacb.example.com. NSEC3 1 1 123 aabb00123456bbccdd k1a2vr9c269jummpru5d68qllbfmtgcb A MX RRSIG ++k1a2vr9c269jummpru5d68qllbfmtacb.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. AARB9z4C1WZUI3WP3QAR7RJXFnN0qEBkEt8ocudxXzms4/7/2l6NNWc= + + ; next closer name, H(www.example.com.) = s1unhcti19bkdr98fegs0v46mbu3t4m3. + s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 123 aabb00123456bbccdd s1unhcti19bkdr98fegs0v46mbu3t4m4 A MX RRSIG +@@ -152,10 +152,10 @@ SECTION ANSWER + SECTION AUTHORITY + example.com. IN SOA ns.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000 + example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFCNGZ+/OfElYQMCZ77O9Lw9rhk7PAhUAmDcvTAst6Bq83qPq3r6c/Dm1nFc= ;{id = 2854} +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. NSEC3 1 1 8 - 6md8numosa4q9ugkffdo1bmm82t5j49s SOA NS MX DNSKEY RRSIG +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCz/LkFOFcaQzVnyySW9ZoVUnxh7gIUdxyS9vqVDzo8pGhFU+3YogN2ZRk= ;{id = 2854} +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. NSEC3 1 1 0 - 4f3cnt8cu22tngec382jj4gde4rb48ub A MX RRSIG +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MCwCFHS+i/OB/V/gYmS1eQTXieXIXGjsAhQQ0Ql7TW/hsUklrb0DfoyhVPG95Q== ;{id = 2854} ++b6fuorg741ufili49mg9j4328ig53sqg.example.com. NSEC3 1 1 123 aabb00123456bbccdd b6fuorg741ufili49mg9j4328ig53sqh SOA NS MX DNSKEY RRSIG ++b6fuorg741ufili49mg9j4328ig53sqg.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. AJlV5car66lq5f0ASx7W47A/OADkARAXzKt9ZLojXze+FWK9JjAX+eA= ++k1a2vr9c269jummpru5d68qllbfmtacb.example.com. NSEC3 1 1 123 aabb00123456bbccdd k1a2vr9c269jummpru5d68qllbfmtgcb A MX RRSIG ++k1a2vr9c269jummpru5d68qllbfmtacb.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. AARB9z4C1WZUI3WP3QAR7RJXFnN0qEBkEt8ocudxXzms4/7/2l6NNWc= + s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 123 aabb00123456bbccdd s1unhcti19bkdr98fegs0v46mbu3t4m4 A MX RRSIG + s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFFSH4klZKke48dYyddYDj17gjTS0AhUAltWicpFLWqW98/Af9Qlx70MH8o4= ;{id = 2854} + +diff --git a/testdata/val_nx_nsec3_collision.rpl b/testdata/val_nx_nsec3_collision.rpl +index 87a55f565..1b1f49e80 100644 +--- a/testdata/val_nx_nsec3_collision.rpl ++++ b/testdata/val_nx_nsec3_collision.rpl +@@ -89,6 +89,17 @@ ns.example.com. IN A 1.2.3.4 + ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} + ENTRY_END + ++ENTRY_BEGIN ++MATCH opcode qtype qname ++ADJUST copy_id ++REPLY QR AA NOERROR ++SECTION QUESTION ++ns.example.com. IN AAAA ++SECTION AUTHORITY ++example.com. IN SOA ns.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000 ++example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFCNGZ+/OfElYQMCZ77O9Lw9rhk7PAhUAmDcvTAst6Bq83qPq3r6c/Dm1nFc= ;{id = 2854} ++ENTRY_END ++ + ; response to DNSKEY priming query + ENTRY_BEGIN + MATCH opcode qtype qname +@@ -163,29 +174,11 @@ STEP 2 TIME_PASSES ELAPSE 0.05 + STEP 10 CHECK_ANSWER + ENTRY_BEGIN + MATCH all +-REPLY QR RD RA DO NXDOMAIN ++REPLY QR RD RA DO SERVFAIL + SECTION QUESTION + www.example.com. IN A + SECTION ANSWER + SECTION AUTHORITY +-example.com. IN SOA ns.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000 +-example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFCNGZ+/OfElYQMCZ77O9Lw9rhk7PAhUAmDcvTAst6Bq83qPq3r6c/Dm1nFc= ;{id = 2854} +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. NSEC3 1 1 123 aabb00123456bbccdd 6md8numosa4q9ugkffdo1bmm82t5j49s A RRSIG +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. NSEC3 1 1 8 - 6md8numosa4q9ugkffdo1bmm82t5j49s SOA NS MX DNSKEY RRSIG +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MCwCFHndWrEEbuzezs/4lxeiMgEuUsUbAhR72gJgd/Zmhf80yoxCauw9k5OkCw== ;{id = 2854} +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. NSEC3 1 1 18 - 4f3cnt8cu22tngec382jj4gde4rb87ub A RRSIG +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. NSEC3 1 1 0 - 4f3cnt8cu22tngec382jj4gde4rb48ub A MX RRSIG +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. NSEC3 1 1 19 - 4f3cnt8cu22tngec382jj4gde4rb87ub A RRSIG +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MCwCFDRwji51WCXJg7W/3+Jx586af5qgAhQPxHegtzu1I/QbvCNrOOON05N1rw== ;{id = 2854} +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 18 - s1unhcti19bkdr98fegs0v46mbu3t4m4 A RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 19 - s1unhcti19bkdr98fegs0v46mbu3t4m4 A RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 20 00 s1unhcti19bkdr98fegs0v46mbu3t4m4 A RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 123 aabb00123456bbccdd s1unhcti19bkdr98fegs0v46mbu3t4m4 A MX RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 20 01 s1unhcti19bkdr98fegs0v46mbu3t4m4 A RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 20 02 s1unhcti19bkdr98fegs0v46mbu3t4m4 A RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 20 03 s1unhcti19bkdr98fegs0v46mbu3t4m4 A RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MCwCFDLy4GbR8ZaKHATVJGnGxzpsuq60AhQ1/pRbXi1ZbcYohzHgWzNC50fC5A== ;{id = 2854} +- + SECTION ADDITIONAL + ENTRY_END + +diff --git a/testdata/val_nx_nsec3_params.rpl b/testdata/val_nx_nsec3_params.rpl +index dd3ab6b57..59bef2be3 100644 +--- a/testdata/val_nx_nsec3_params.rpl ++++ b/testdata/val_nx_nsec3_params.rpl +@@ -88,6 +88,17 @@ ns.example.com. IN A 1.2.3.4 + ns.example.com. 3600 IN RRSIG A 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCMSWxVehgOQLoYclB9PIAbNP229AIUeH0vNNGJhjnZiqgIOKvs1EhzqAo= ;{id = 2854} + ENTRY_END + ++ENTRY_BEGIN ++MATCH opcode qtype qname ++ADJUST copy_id ++REPLY QR AA NOERROR ++SECTION QUESTION ++ns.example.com. IN AAAA ++SECTION AUTHORITY ++example.com. IN SOA ns.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000 ++example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFCNGZ+/OfElYQMCZ77O9Lw9rhk7PAhUAmDcvTAst6Bq83qPq3r6c/Dm1nFc= ;{id = 2854} ++ENTRY_END ++ + ; response to DNSKEY priming query + ENTRY_BEGIN + MATCH opcode qtype qname +@@ -144,20 +155,11 @@ ENTRY_END + STEP 10 CHECK_ANSWER + ENTRY_BEGIN + MATCH all +-REPLY QR RD RA DO NXDOMAIN ++REPLY QR RD RA DO SERVFAIL + SECTION QUESTION + www.example.com. IN A + SECTION ANSWER + SECTION AUTHORITY +-example.com. IN SOA ns.example.com. hostmaster.example.com. 2007090400 28800 7200 604800 18000 +-example.com. 3600 IN RRSIG SOA 3 2 3600 20070926134150 20070829134150 2854 example.com. MC0CFCNGZ+/OfElYQMCZ77O9Lw9rhk7PAhUAmDcvTAst6Bq83qPq3r6c/Dm1nFc= ;{id = 2854} +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. NSEC3 1 1 8 - 6md8numosa4q9ugkffdo1bmm82t5j49s SOA NS MX DNSKEY RRSIG +-6md8numosa4q9ugkffdo1bmm82t5j39s.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFQCz/LkFOFcaQzVnyySW9ZoVUnxh7gIUdxyS9vqVDzo8pGhFU+3YogN2ZRk= ;{id = 2854} +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. NSEC3 1 1 0 - 4f3cnt8cu22tngec382jj4gde4rb48ub A MX RRSIG +-4f3cnt8cu22tngec382jj4gde4rb46ub.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MCwCFHS+i/OB/V/gYmS1eQTXieXIXGjsAhQQ0Ql7TW/hsUklrb0DfoyhVPG95Q== ;{id = 2854} +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. NSEC3 1 1 123 aabb00123456bbccdd s1unhcti19bkdr98fegs0v46mbu3t4m4 A MX RRSIG +-s1unhcti19bkdr98fegs0v46mbu3t4m2.example.com. 3600 IN RRSIG NSEC3 3 3 3600 20070926135752 20070829135752 2854 example.com. MC0CFFSH4klZKke48dYyddYDj17gjTS0AhUAltWicpFLWqW98/Af9Qlx70MH8o4= ;{id = 2854} +- + SECTION ADDITIONAL + ENTRY_END + +diff --git a/validator/val_nsec3.c b/validator/val_nsec3.c +index 998fcc4e3..92d853825 100644 +--- a/validator/val_nsec3.c ++++ b/validator/val_nsec3.c +@@ -456,6 +456,67 @@ filter_init(struct nsec3_filter* filter, struct ub_packed_rrset_key** list, + } + } + ++/** Check if the NSEC3s have the same parameter set. */ ++static int ++param_set_same(struct nsec3_filter* flt, char** reason) ++{ ++ size_t rrsetnum; ++ int rrnum; ++ struct ub_packed_rrset_key* rrset; ++ int have_params = 0; ++ int first_algo = 0; ++ size_t first_iter = 0; ++ uint8_t* first_salt = NULL; ++ size_t first_saltlen = 0; ++ ++ /* If the NSEC3 parameter sets have distinct values, then they are ++ * from different NSEC3 chains, and we do not want that. */ ++ for(rrset=filter_first(flt, &rrsetnum, &rrnum); rrset; ++ rrset=filter_next(flt, &rrsetnum, &rrnum)) { ++ if(!have_params) { ++ first_algo = nsec3_get_algo(rrset, rrnum); ++ first_iter = nsec3_get_iter(rrset, rrnum); ++ if(!nsec3_get_salt(rrset, rrnum, &first_salt, ++ &first_saltlen)) { ++ verbose(VERB_ALGO, "NSEC3 salt malformed"); ++ if(reason) ++ *reason = "NSEC3 salt malformed"; ++ return 0; ++ } ++ have_params = 1; ++ } else { ++ uint8_t* salt = NULL; ++ size_t saltlen = 0; ++ if(nsec3_get_algo(rrset, rrnum) != first_algo) { ++ verbose(VERB_ALGO, "NSEC3 algorithm mismatch"); ++ if(reason) ++ *reason = "NSEC3 algorithm mismatch"; ++ return 0; ++ } ++ if(nsec3_get_iter(rrset, rrnum) != first_iter) { ++ verbose(VERB_ALGO, "NSEC3 iterations mismatch"); ++ if(reason) ++ *reason = "NSEC3 iterations mismatch"; ++ return 0; ++ } ++ if(!nsec3_get_salt(rrset, rrnum, &salt, &saltlen)) { ++ verbose(VERB_ALGO, "NSEC3 salt malformed"); ++ if(reason) ++ *reason = "NSEC3 salt malformed"; ++ return 0; ++ } ++ if(saltlen != first_saltlen || ++ memcmp(salt, first_salt, saltlen) != 0) { ++ verbose(VERB_ALGO, "NSEC3 salt mismatch"); ++ if(reason) ++ *reason = "NSEC3 salt mismatch"; ++ return 0; ++ } ++ } ++ } ++ return 1; ++} ++ + /** + * Find max iteration count using config settings and key size + * @param ve: validator environment with iteration count config settings. +@@ -1192,6 +1253,8 @@ nsec3_prove_nameerror(struct module_env* env, struct val_env* ve, + filter_init(&flt, list, num, qinfo); /* init RR iterator */ + if(!flt.zone) + return sec_status_bogus; /* no RRs */ ++ if(!param_set_same(&flt, NULL)) ++ return sec_status_bogus; /* nsec3 params from distinct chains*/ + if(nsec3_iteration_count_high(ve, &flt, kkey)) + return sec_status_insecure; /* iteration count too high */ + log_nametypeclass(VERB_ALGO, "start nsec3 nameerror proof, zone", +@@ -1378,6 +1441,8 @@ nsec3_prove_nodata(struct module_env* env, struct val_env* ve, + filter_init(&flt, list, num, qinfo); /* init RR iterator */ + if(!flt.zone) + return sec_status_bogus; /* no RRs */ ++ if(!param_set_same(&flt, NULL)) ++ return sec_status_bogus; /* nsec3 params from distinct chains*/ + if(nsec3_iteration_count_high(ve, &flt, kkey)) + return sec_status_insecure; /* iteration count too high */ + return nsec3_do_prove_nodata(env, &flt, ct, qinfo, calc); +@@ -1401,6 +1466,8 @@ nsec3_prove_wildcard(struct module_env* env, struct val_env* ve, + filter_init(&flt, list, num, qinfo); /* init RR iterator */ + if(!flt.zone) + return sec_status_bogus; /* no RRs */ ++ if(!param_set_same(&flt, NULL)) ++ return sec_status_bogus; /* nsec3 params from distinct chains*/ + if(nsec3_iteration_count_high(ve, &flt, kkey)) + return sec_status_insecure; /* iteration count too high */ + +@@ -1503,6 +1570,8 @@ nsec3_prove_nods(struct module_env* env, struct val_env* ve, + *reason = "no NSEC3 records"; + return sec_status_bogus; /* no RRs */ + } ++ if(!param_set_same(&flt, reason)) ++ return sec_status_bogus; /* nsec3 params from distinct chains*/ + if(nsec3_iteration_count_high(ve, &flt, kkey)) + return sec_status_insecure; /* iteration count too high */ + +@@ -1596,6 +1665,8 @@ nsec3_prove_nxornodata(struct module_env* env, struct val_env* ve, + filter_init(&flt, list, num, qinfo); /* init RR iterator */ + if(!flt.zone) + return sec_status_bogus; /* no RRs */ ++ if(!param_set_same(&flt, NULL)) ++ return sec_status_bogus; /* nsec3 params from distinct chains*/ + if(nsec3_iteration_count_high(ve, &flt, kkey)) + return sec_status_insecure; /* iteration count too high */ + diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index e41e2dc065..d703b27506 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -11,6 +11,7 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5308494bc0590c0cb036afd781d78f06" SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;tag=release-${PV} \ file://run-ptest \ + file://CVE-2026-33278.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:02 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97893 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E7039C79FBB for ; Thu, 10 Sep 2026 23:09:56 +0000 (UTC) Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27765.1789081790522084692 for ; Thu, 10 Sep 2026 16:09:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=BBSqBbSg; spf=pass (domain: gmail.com, ip: 209.85.214.181, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-2ceab75934dso2501795ad.2 for ; Thu, 10 Sep 2026 16:09:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081790; x=1789686590; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=T8mH5jRtdfmGCGt4vFs1VOb0W1NM+62Ty9jk+G53yrA=; b=BBSqBbSgqbj5Ab9ufuyL4aVqRg2YFdkbCwANzjkFLyklHRsY6c62mP4gIZN600/X1j 0b22TbwQTpOpxTJAH2lianTWA3A4xkt6c4BbFo11qsHOIXlgxtFNE/0ey3KNkdyD6wi2 ugR+pGQE+mKK+T9gt587o1FKSnCtlFnGvPXLZloO1HPYhBHf+i8kKATb1fDUOc5wcdyp YZPtuWm8c1X3XXWB2ISyA0mc802cP2wBUUuwnMBbZtEuEjDYStsTvOI2k+nI4udmrIO7 5pFZ7HzQsfQYkjBTYt8yVt+cSdbAvI/JU0HmuxccfCKlod6qQOKs8FsGwSGy7yeCC+aw sGSw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081790; x=1789686590; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=T8mH5jRtdfmGCGt4vFs1VOb0W1NM+62Ty9jk+G53yrA=; b=KzpOWsHqS6vTjMqUPU5EYBhrPNfLit1UcBHBqTdmgC7LuGLu/CXpjD9Aozl0xSw8Qx BC+eess0ST8mQPFLm+r+aKahfm+QbkdHyysFcg6rwlIKdlGtJaAR73tirjtGwmZ31THW N/qTfKAkElqeWYDfIlhhto7df8GPKIrxIlKoqszS23BjMsakJqrMBDiV6N/ZPJEhWisr /KYiY0KpAlORxUJjVZk3CW9JV0fnn9trs3vdy8DnC8WRTg4k4jJbpUlHguEOGxcXJLpl 4XlqliVXeWSFTDBlRxaF/tDdA53DFqLWjoYzv38OaQivSPzWDNHWKhbRnVks/Yl2Kkua aJjQ== X-Gm-Message-State: AFuF++liocyt/7nyggHfk/4KgQ3zxZEccLC2dMBnDqWk7u3YVTa8aBIT bJAcajsjR0c7/tMPCDtRGxSseZC2wi+EHTK6egoSv6JKxeQ0+pAAebufy8IFBQ== X-Gm-Gg: AYBFou14dGdRDfhAIRadE9d4PBgSBYJ4ltAfRtmyUAl9Vj8BSPGeVQB69AJ9emhRgRO xbvHxHr7OsKdm/rmE3d2CmqUjMjTp705gPZwmqVCqVCuTHqXswfDzOqJYcv5WmPuap+9QCq83jA KJER01xYYTL0j32nYSqCbgMzKg4ZqGpFj/ZSvB9av6CAJIodPcDiGEGxJcR30rmhK+s2m7jw9RE +WekHB9BdO98E1qIscQ2vX7HtfbSiCwJba8BUEcs5ZlE1tYOP7KM9/uf4NVbYb/jglPegKbOrkj QdDqvcQU3OFQB9YgBjcY1TcLVmD6YZyL4qhXA626MnqGSAZZSb8kDaHeFccS9O/urSYWOx2Fbwo rNDQA2QUMIr2KRLv4uJJZdCFjG7/NVXXzBNXzJS8S1LvAZkT2VkgdBqTpUEz9qxk4/0EH5Y86ie op1rpMdSa6Cs2C95iieJ2DxlPjVnL0sYKCkM2Y+AXxtjUUCqoTMPfPTiA7BH4NxFwVBpiOa2g5W 6NoHWpa1ODV0JfObQBjPeE= X-Received: by 2002:a17:90b:3c8d:b0:38f:de97:b06 with SMTP id 98e67ed59e1d1-39d9bbdbac7mr1862047a91.5.1789081789597; Thu, 10 Sep 2026 16:09:49 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.09.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:09:49 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 3/32] unbound: patch CVE-2026-42944 Date: Fri, 11 Sep 2026 11:09:02 +1200 Message-ID: <20260910230932.173913-3-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:09:56 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129921 From: Ankur Tyagi Backport commit[1] needed to cherry-pick the fix. Details: https://nvd.nist.gov/vuln/detail/cve-2026-42944 [1]https://github.com/NLnetLabs/unbound/commit/44659cb3bf4601d2daa19a0d51ac5af54bc698bc Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-42944-1.patch | 61 +++++ .../unbound/unbound/CVE-2026-42944-2.patch | 231 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 2 + 3 files changed, 294 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-1.patch create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-2.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-1.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-1.patch new file mode 100644 index 0000000000..211a89d31f --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-1.patch @@ -0,0 +1,61 @@ +From 812df79447b34af62636f65342809027bb6d5b58 Mon Sep 17 00:00:00 2001 +From: Yorgos Thessalonikefs +Date: Wed, 31 Dec 2025 16:22:15 +0100 +Subject: [PATCH] - Use the same EDE removal logic when encoding errors as when + encoding replies. + +(cherry picked from commit 44659cb3bf4601d2daa19a0d51ac5af54bc698bc) + +CVE: CVE-2026-42944 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/44659cb3bf4601d2daa19a0d51ac5af54bc698bc] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + util/data/msgencode.c | 24 ++++++++++++++++-------- + 1 file changed, 16 insertions(+), 8 deletions(-) + +diff --git a/util/data/msgencode.c b/util/data/msgencode.c +index 84aa3b9e7..4263aa41e 100644 +--- a/util/data/msgencode.c ++++ b/util/data/msgencode.c +@@ -1115,22 +1115,30 @@ extended_error_encode(sldns_buffer* buf, uint16_t rcode, + sldns_buffer_write_u16(buf, qinfo->qclass); + } + sldns_buffer_flip(buf); +- if(edns) { ++ if(edns && edns->edns_present) { ++ uint16_t edns_field_size, ede_size, ede_txt_size; + struct edns_data es = *edns; + es.edns_version = EDNS_ADVERTISED_VERSION; + es.udp_size = EDNS_ADVERTISED_SIZE; + es.ext_rcode = (uint8_t)(rcode >> 4); + es.bits &= EDNS_DO; +- if(sldns_buffer_limit(buf) + calc_edns_field_size(&es) > +- edns->udp_size) { ++ /* EDEs are optional. If space is a concern try in order: ++ * - removing any EXTRA-TEXT fields from explicit EDEs, or ++ * - removing all EDEs, ++ * to see if EDNS can fit. */ ++ edns_field_size = calc_edns_field_size(&es); ++ ede_size = calc_ede_option_size(&es, &ede_txt_size); ++ if(edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size) ++ attach_edns_record_max_msg_sz(buf, &es, edns->udp_size); ++ else if(edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size - ede_txt_size) { ++ ede_trim_text(&es.opt_list_inplace_cb_out); ++ ede_trim_text(&es.opt_list_out); ++ attach_edns_record_max_msg_sz(buf, &es, edns->udp_size); ++ } else if(edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size - ede_size) { + edns_opt_list_remove(&es.opt_list_inplace_cb_out, LDNS_EDNS_EDE); + edns_opt_list_remove(&es.opt_list_out, LDNS_EDNS_EDE); +- if(sldns_buffer_limit(buf) + calc_edns_field_size(&es) > +- edns->udp_size) { +- return; +- } ++ attach_edns_record_max_msg_sz(buf, &es, edns->udp_size); + } +- attach_edns_record(buf, &es); + } + } + diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-2.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-2.patch new file mode 100644 index 0000000000..707ad9577d --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42944-2.patch @@ -0,0 +1,231 @@ +From c4916b3b373b643f7e359de31259785cfc3b95d9 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:13:55 +0200 +Subject: [PATCH] - Fix CVE-2026-42944, Heap overflow and crash with multiple + nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto + Networks, for the report. + +(cherry picked from commit fe946ba4e935a1528e6866e108e5bc9e7533ae18) + +CVE: CVE-2026-42944 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/fe946ba4e935a1528e6866e108e5bc9e7533ae18] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + testcode/unitmain.c | 4 ++-- + util/data/msgencode.c | 36 +++++++++++++++++++++++------------- + util/data/msgencode.h | 4 ++-- + util/data/msgparse.c | 10 +++++++--- + 4 files changed, 34 insertions(+), 20 deletions(-) + +diff --git a/testcode/unitmain.c b/testcode/unitmain.c +index 07c016d7b..beb10ba45 100644 +--- a/testcode/unitmain.c ++++ b/testcode/unitmain.c +@@ -1092,7 +1092,7 @@ static void edns_ede_encode_notxt_fit_test( struct query_info* qinfo, + { + struct edns_data edns; + sldns_buffer* pkt; +- uint16_t edns_field_size, ede_txt_size; ++ size_t edns_field_size, ede_txt_size; + int found_ede = 0, found_ede_other = 0, found_ede_txt = 0; + int found_other_edns = 0; + edns_ede_encode_setup(&edns, region); +@@ -1123,7 +1123,7 @@ static void edns_ede_encode_no_fit_test( struct query_info* qinfo, + { + struct edns_data edns; + sldns_buffer* pkt; +- uint16_t edns_field_size, ede_size, ede_txt_size; ++ size_t edns_field_size, ede_size, ede_txt_size; + int found_ede = 0, found_ede_other = 0, found_ede_txt = 0; + int found_other_edns = 0; + edns_ede_encode_setup(&edns, region); +diff --git a/util/data/msgencode.c b/util/data/msgencode.c +index 4263aa41e..7bc55a54e 100644 +--- a/util/data/msgencode.c ++++ b/util/data/msgencode.c +@@ -804,7 +804,7 @@ reply_info_encode(struct query_info* qinfo, struct reply_info* rep, + return 1; + } + +-uint16_t ++size_t + calc_edns_field_size(struct edns_data* edns) + { + size_t rdatalen = 0; +@@ -840,7 +840,7 @@ calc_edns_option_size(struct edns_data* edns, uint16_t code) + } + + uint16_t +-calc_ede_option_size(struct edns_data* edns, uint16_t* txt_size) ++calc_ede_option_size(struct edns_data* edns, size_t* txt_size) + { + size_t rdatalen = 0; + struct edns_option* opt; +@@ -942,6 +942,10 @@ attach_edns_record_max_msg_sz(sldns_buffer* pkt, struct edns_data* edns, + padding_option = opt; + continue; + } ++ if(sldns_buffer_position(pkt) + opt->opt_len + 4 > max_msg_sz) ++ break; /* no space for it */ ++ if(!sldns_buffer_available(pkt, 4 + opt->opt_len)) ++ break; + sldns_buffer_write_u16(pkt, opt->opt_code); + sldns_buffer_write_u16(pkt, opt->opt_len); + if(opt->opt_len != 0) +@@ -952,12 +956,18 @@ attach_edns_record_max_msg_sz(sldns_buffer* pkt, struct edns_data* edns, + padding_option = opt; + continue; + } ++ if(sldns_buffer_position(pkt) + opt->opt_len + 4 > max_msg_sz) ++ break; /* no space for it */ ++ if(!sldns_buffer_available(pkt, 4 + opt->opt_len)) ++ break; + sldns_buffer_write_u16(pkt, opt->opt_code); + sldns_buffer_write_u16(pkt, opt->opt_len); + if(opt->opt_len != 0) + sldns_buffer_write(pkt, opt->opt_data, opt->opt_len); + } +- if (padding_option && edns->padding_block_size ) { ++ if (padding_option && edns->padding_block_size && ++ sldns_buffer_position(pkt)+4 <= max_msg_sz && ++ sldns_buffer_available(pkt, 4) /* if there is space for it */) { + size_t pad_pos = sldns_buffer_position(pkt); + size_t msg_sz = ((pad_pos + 3) / edns->padding_block_size + 1) + * edns->padding_block_size; +@@ -1001,7 +1011,7 @@ reply_info_answer_encode(struct query_info* qinf, struct reply_info* rep, + { + uint16_t flags; + unsigned int attach_edns = 0; +- uint16_t edns_field_size, ede_size, ede_txt_size; ++ size_t edns_field_size, ede_size, ede_txt_size; + + if(!cached || rep->authoritative) { + /* original flags, copy RD and CD bits from query. */ +@@ -1028,12 +1038,12 @@ reply_info_answer_encode(struct query_info* qinf, struct reply_info* rep, + * calculate sizes once here */ + edns_field_size = calc_edns_field_size(edns); + ede_size = calc_ede_option_size(edns, &ede_txt_size); +- if(sldns_buffer_capacity(pkt) < udpsize) ++ if(sldns_buffer_capacity(pkt) < (size_t)udpsize) + udpsize = sldns_buffer_capacity(pkt); + if(!edns || !edns->edns_present) { + attach_edns = 0; + /* EDEs are optional, try to fit anything else before them */ +- } else if(udpsize < LDNS_HEADER_SIZE + edns_field_size - ede_size) { ++ } else if((size_t)udpsize < (size_t)LDNS_HEADER_SIZE + edns_field_size - ede_size) { + /* packet too small to contain edns, omit it. */ + attach_edns = 0; + } else { +@@ -1047,13 +1057,13 @@ reply_info_answer_encode(struct query_info* qinf, struct reply_info* rep, + return 0; + } + if(attach_edns) { +- if(udpsize >= sldns_buffer_limit(pkt) + edns_field_size) ++ if((size_t)udpsize >= sldns_buffer_limit(pkt) + edns_field_size) + attach_edns_record_max_msg_sz(pkt, edns, udpsize); +- else if(udpsize >= sldns_buffer_limit(pkt) + edns_field_size - ede_txt_size) { ++ else if((size_t)udpsize >= sldns_buffer_limit(pkt) + edns_field_size - ede_txt_size) { + ede_trim_text(&edns->opt_list_inplace_cb_out); + ede_trim_text(&edns->opt_list_out); + attach_edns_record_max_msg_sz(pkt, edns, udpsize); +- } else if(udpsize >= sldns_buffer_limit(pkt) + edns_field_size - ede_size) { ++ } else if((size_t)udpsize >= sldns_buffer_limit(pkt) + edns_field_size - ede_size) { + edns_opt_list_remove(&edns->opt_list_inplace_cb_out, LDNS_EDNS_EDE); + edns_opt_list_remove(&edns->opt_list_out, LDNS_EDNS_EDE); + attach_edns_record_max_msg_sz(pkt, edns, udpsize); +@@ -1116,7 +1126,7 @@ extended_error_encode(sldns_buffer* buf, uint16_t rcode, + } + sldns_buffer_flip(buf); + if(edns && edns->edns_present) { +- uint16_t edns_field_size, ede_size, ede_txt_size; ++ size_t edns_field_size, ede_size, ede_txt_size; + struct edns_data es = *edns; + es.edns_version = EDNS_ADVERTISED_VERSION; + es.udp_size = EDNS_ADVERTISED_SIZE; +@@ -1128,13 +1138,13 @@ extended_error_encode(sldns_buffer* buf, uint16_t rcode, + * to see if EDNS can fit. */ + edns_field_size = calc_edns_field_size(&es); + ede_size = calc_ede_option_size(&es, &ede_txt_size); +- if(edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size) ++ if((size_t)edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size) + attach_edns_record_max_msg_sz(buf, &es, edns->udp_size); +- else if(edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size - ede_txt_size) { ++ else if((size_t)edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size - ede_txt_size) { + ede_trim_text(&es.opt_list_inplace_cb_out); + ede_trim_text(&es.opt_list_out); + attach_edns_record_max_msg_sz(buf, &es, edns->udp_size); +- } else if(edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size - ede_size) { ++ } else if((size_t)edns->udp_size >= sldns_buffer_limit(buf) + edns_field_size - ede_size) { + edns_opt_list_remove(&es.opt_list_inplace_cb_out, LDNS_EDNS_EDE); + edns_opt_list_remove(&es.opt_list_out, LDNS_EDNS_EDE); + attach_edns_record_max_msg_sz(buf, &es, edns->udp_size); +diff --git a/util/data/msgencode.h b/util/data/msgencode.h +index 08fcb59b8..64569555d 100644 +--- a/util/data/msgencode.h ++++ b/util/data/msgencode.h +@@ -106,7 +106,7 @@ void qinfo_query_encode(struct sldns_buffer* pkt, struct query_info* qinfo); + * @param edns: edns data or NULL. + * @return octets to reserve for EDNS. + */ +-uint16_t calc_edns_field_size(struct edns_data* edns); ++size_t calc_edns_field_size(struct edns_data* edns); + + /** + * Calculate the size of a specific EDNS option in packet. +@@ -127,7 +127,7 @@ uint16_t calc_edns_option_size(struct edns_data* edns, uint16_t code); + * extra text. + * @return octets the option will take up. + */ +-uint16_t calc_ede_option_size(struct edns_data* edns, uint16_t* txt_size); ++uint16_t calc_ede_option_size(struct edns_data* edns, size_t* txt_size); + + /** + * Attach EDNS record to buffer. Buffer has complete packet. There must +diff --git a/util/data/msgparse.c b/util/data/msgparse.c +index 6963d8501..2d0955631 100644 +--- a/util/data/msgparse.c ++++ b/util/data/msgparse.c +@@ -950,6 +950,7 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + struct comm_reply* repinfo, uint32_t now, struct regional* region, + struct cookie_secrets* cookie_secrets) + { ++ int nsid_seen = 0, cookie_seen = 0, padding_seen = 0; + /* To respond with a Keepalive option, the client connection must have + * received one message with a TCP Keepalive EDNS option, and that + * option must have 0 length data. Subsequent messages sent on that +@@ -984,8 +985,9 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + /* handle parse time edns options here */ + switch(opt_code) { + case LDNS_EDNS_NSID: +- if (!cfg || !cfg->nsid) ++ if (!cfg || !cfg->nsid || nsid_seen) + break; ++ nsid_seen = 1; + if(!edns_opt_list_append(&edns->opt_list_out, + LDNS_EDNS_NSID, cfg->nsid_len, + cfg->nsid, region)) { +@@ -1027,8 +1029,9 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + + case LDNS_EDNS_PADDING: + if(!cfg || !cfg->pad_responses || +- !c || c->type != comm_tcp ||!c->ssl) ++ !c || c->type != comm_tcp ||!c->ssl || padding_seen) + break; ++ padding_seen = 1; + if(!edns_opt_list_append(&edns->opt_list_out, + LDNS_EDNS_PADDING, + 0, NULL, region)) { +@@ -1039,8 +1042,9 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + break; + + case LDNS_EDNS_COOKIE: +- if(!cfg || !cfg->do_answer_cookie || !repinfo) ++ if(!cfg || !cfg->do_answer_cookie || !repinfo || cookie_seen) + break; ++ cookie_seen = 1; + if(opt_len != 8 && (opt_len < 16 || opt_len > 40)) { + verbose(VERB_ALGO, "worker request: " + "badly formatted cookie"); diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index d703b27506..b8853c9d63 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -12,6 +12,8 @@ LIC_FILES_CHKSUM = "file://LICENSE;md5=5308494bc0590c0cb036afd781d78f06" SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;tag=release-${PV} \ file://run-ptest \ file://CVE-2026-33278.patch \ + file://CVE-2026-42944-1.patch \ + file://CVE-2026-42944-2.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:03 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97895 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0D76FC88E46 for ; Thu, 10 Sep 2026 23:09:57 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27828.1789081793563475251 for ; Thu, 10 Sep 2026 16:09:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ijTduu+a; spf=pass (domain: gmail.com, ip: 74.125.227.140, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj2-f12.google.com with SMTP id d9443c01a7336-2d8fb334ddcso2017015ad.0 for ; Thu, 10 Sep 2026 16:09:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081793; x=1789686593; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xE6JmkrrMF7AeZfCgYkHbZnvODA63fw2yWFLRjKZ0I0=; b=ijTduu+aDlSLEbJBH5NAmVhBGtiYh8nnVnv8eUtrkaEfb/WD/kmZUYEX8AZeLCgxOa mUZChfummAtIGIVK0aNDFGijeI8onH23F9Q6DuVivywhPGa/uH3RDAAyz2ciyAmFwuPE OAXpb6W8fG5fX7JmUmydoC76T9qGOcZ6Jqf1CPtyiJ5Gsy3KIs3P+dESN0fxTMPk346U 8KZEsuqyUDGAFnfAQMAw9v0fSr1XFfE/AVQ/ZUR5aqmeG9/j0igWELyqRhn1ylyNQ017 lSWe3fJ5HCUabJ+esIJsi49SmtNBsuLjUtIBuqWIAWPDZdaZ/DhA066u84ME47JwfVLb W6lA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081793; x=1789686593; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=xE6JmkrrMF7AeZfCgYkHbZnvODA63fw2yWFLRjKZ0I0=; b=rLOMTrW9MaZcl3OLdikUqPGRLszIrkxii8nk/bNnmCe+QsnV23gH+Vu44QRzXcOBxk T0hKRyPQpHXpRE8r0X5GMjSaMxSt9WXZsNRjny5t2j/CPheEdGNfZG0aRhCR81gZNCv3 UVD5jIKLiNzhA9IynB1q7rmlHc3wFN2JKpyk40vFSQro0ckovI1By/FBxLsyagawUp6E SuOf2Bez2zZ9j+8vnJw1cqRpoS+BK8R7zqUjuh7rbgS82H45l60D/+nQS1yIXnU0+xHT 7s1gZ53VSEaqpXZlV8YG9Uy/AxJAsfieTyvP0h8YrkFKQRO9g2DyQkhOivIaFrBVmHBf qGlQ== X-Gm-Message-State: AFuF++kKniH01pv1UOOz6wBEkDe0sjySFkmFCPk/MBoWiNj1YnW/Tsrb jGQElHN6U+YXKHnRzXW5jF1TPnsi0zaFGxBkBmdtul/Wa0v9RjfDmETde07VSg== X-Gm-Gg: AYBFou2YpS2rp3JC2PRdd7DnOwLaCysW8EVAdWE57kLP030wBv7oNK+U3YUHT7jG010 V83VDC0QPxXXXw5T3ktaE8mgNUQ9gZE7CpVydvWkaShVcByFon5I2N0mH8bFqpiQVe2SIB95wYH hwRlf5oC5cNjsjahFLmJCeiTpkqQY6hEV5sPpwcvzCQ5OLPw4wYzIigLdGJJuuZhHygpnBSvB6w EIg4YHBTus4/Nuyct6Qk2AGVWDwPegdeT9Ii8ux2muLQ+DQ6Bh9z1YSt/wIbOlWpFa2u1Ndb8no N12PObqiULmRMGOu1w1xtEPWfQ8j26uPl25jwNePYVZagsTeJoBHkcaCrRPn2w5R7m9E87ox8Oe lWhGULMjCao3CEaH2VBQHaAeugBvyi2PhK/D7nIcdOPRVFInk8Lir84O01PXZrNXOrlMIvCV8vc 2nld2yr2W+k1k9k481bmOO5/ymEKO4c8uwq/X7oNScjgQy3b8+MbAOablyUeKlTRtH9UZidRL9q P8JCYZwSimAG1GTgMyDeFE= X-Received: by 2002:a17:90b:3dc6:b0:398:bc52:825b with SMTP id 98e67ed59e1d1-39d9c3aeedfmr1797985a91.21.1789081792704; Thu, 10 Sep 2026 16:09:52 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.09.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:09:52 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 4/32] unbound: patch CVE-2026-42959 Date: Fri, 11 Sep 2026 11:09:03 +1200 Message-ID: <20260910230932.173913-4-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:09:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129922 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-42959 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-42959.patch | 36 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-42959.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-42959.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42959.patch new file mode 100644 index 0000000000..b8df4f66c4 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42959.patch @@ -0,0 +1,36 @@ +From 42e04de6baba41208c80f8003f2dca58ebf66468 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:14:32 +0200 +Subject: [PATCH] - Fix CVE-2026-42959, Crash during DNSSEC validation of + malicious content. Thanks to Qifan Zhang, Palo Alto Networks, for the + report. + +(cherry picked from commit 94d5babaee22a016e376bdcfee2b9bb40360367c) + +CVE: CVE-2026-42959 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/94d5babaee22a016e376bdcfee2b9bb40360367c] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + validator/val_utils.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +diff --git a/validator/val_utils.c b/validator/val_utils.c +index 549264d76..4495695ac 100644 +--- a/validator/val_utils.c ++++ b/validator/val_utils.c +@@ -1066,10 +1066,10 @@ val_fill_reply(struct reply_info* chase, struct reply_info* orig, + if(query_dname_compare(name, + orig->rrsets[i]->rk.dname) == 0) + chase->rrsets[chase->an_numrrsets +- +orig->ns_numrrsets+chase->ar_numrrsets++] ++ +chase->ns_numrrsets+chase->ar_numrrsets++] + = orig->rrsets[i]; + } else if(rrset_has_signer(orig->rrsets[i], name, len)) { +- chase->rrsets[chase->an_numrrsets+orig->ns_numrrsets+ ++ chase->rrsets[chase->an_numrrsets+chase->ns_numrrsets+ + chase->ar_numrrsets++] = orig->rrsets[i]; + } + } diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index b8853c9d63..3adc98621e 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -14,6 +14,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-33278.patch \ file://CVE-2026-42944-1.patch \ file://CVE-2026-42944-2.patch \ + file://CVE-2026-42959.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:04 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97897 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 051B3C79FBB for ; Thu, 10 Sep 2026 23:10:07 +0000 (UTC) Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27831.1789081797508297170 for ; Thu, 10 Sep 2026 16:09:57 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=d7pf8rq2; spf=pass (domain: gmail.com, ip: 209.85.216.50, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-39675172593so297970a91.2 for ; Thu, 10 Sep 2026 16:09:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081797; x=1789686597; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JsQnN870XmQWuvMdpafyf+ouEAY3mIjP1daGvGLa+2g=; b=d7pf8rq2O0XF1MKrxIKkc7GyFctRxJi8EVX0aVTpWltPI62qbsPLt6sFvLZXbAyN/Y KnqNfLtf2OPWoxG1vNSZPBmZ+FPiuEGAXj48V+D5zvOg/nmWIgfaiNP5I90IMQM5eByt fg6JzcPgBg8zWUJYePx6ky35n7pw4E1NQZxETzbKOeNOK05acW7lmx3HaxXR8DZzgKR9 03h7/wBXmBVCgpcG70i27n6aoZZZI8dg0aGj9Tce5dMxnOgM1SgSTnwZpRtwkfZhXjvi raxXNm01oSZ5NK01u4BHxOjw2ff+Pxi4E+KtVJ2DDsXWhXr2dt70CfhJQrj+4Hz/BGoJ JfuQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081797; x=1789686597; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=JsQnN870XmQWuvMdpafyf+ouEAY3mIjP1daGvGLa+2g=; b=cgR3cEd1br2ncarKIeRRafvfOpeNwYTuKiZnj9wGCXrHGtLqnZV17mGEJnjfKMtHEx tCVj/Pqf5+te4G5kOVBp0jMOCZNb3k5UoJ2gaO+RGR4idgQwiaUe+njOmDM3TrMhMB8P u9SWbM35OD2uAQavoqGrM4rFlGP6Vy2JlYVW8s2NPTyjon5Aa8a1WUjnUFb0Au/sKDR3 uPI5LxrR/Mpd0zdWOd0SWNy/u1sZoOrHWneBvFQs/BtpwariWaxTj1TT+ZbQoHU5XVDk meYvo88jc2DetGSUcxNdaSQWIxx+bTcEW8yDFmIjuurUy06C6gvC4yJPCnrv2UdbzOGJ HxSw== X-Gm-Message-State: AFuF++kruYnpmv0HJXJWEidNsOKw/hM8uVP719fNZyiOAKE4RMNkyok8 5fF3f1485q6ObHol2dEhwIV9Gi2f+QdreHHvnY+O2JOd65K1i2Rl1fY0ocpuuw== X-Gm-Gg: AYBFou0Q7lqfEPu9tPNM7k/uvW/qe+Y4un15F2l7LSUY0nRtS98y1aDY7yBeNvP0ZjF NEk+733ruuXTr3NF5sX+OkG/RWRJ3IHvm//p9QFS6+VI0ffNB2dNIbzl4CNGmjjZ80ppK3pyVo2 cOinh9sT4av84DpA2W4wgA8Q41w7eEI9jT/XAJXumDvoM/pORMBG3kCXPWJVf4YvosZlGEfk1vV yiBGfdNX0tfiDf8endXLGnDNvkPCk9I3Kq8lQovp1DHQMhzD1qPZO1pGCWWGHBFH9JqMXfclEwq cggDPeME/3x/MpOFS/XXSxql73WSP20Kfn4fH+droTyQNJ6kHJrnRxh1eTMR+eNf+wKdP6D3En7 DVsChau/fULsbzyVnNrDpqxF8EQ3cyscAmmvU+fXzWeWHNNbNeTHNj0MdohkaYWcxTOenDRYNcO QD9CJpIszD0vw80Y+rQjKeudiLltEZnDKPE+2va9GLA+PKOQmNupVJ58NIg07lJVqLQ5yl/XDsG ufzBbIc63530LhZEOi/+uR7oA== X-Received: by 2002:a17:90b:57c5:b0:38e:9045:bac0 with SMTP id 98e67ed59e1d1-39d9bc1b0eemr1830063a91.5.1789081796774; Thu, 10 Sep 2026 16:09:56 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.09.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:09:56 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 5/32] unbound: patch CVE-2026-32792 Date: Fri, 11 Sep 2026 11:09:04 +1200 Message-ID: <20260910230932.173913-5-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129923 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-32792 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-32792.patch | 31 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 32 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-32792.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-32792.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-32792.patch new file mode 100644 index 0000000000..5b1a248979 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-32792.patch @@ -0,0 +1,31 @@ +From 14bb8321708507fe138d3d6e77e51a9b86ea75b8 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:15:30 +0200 +Subject: [PATCH] - Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks + to Andrew Griffiths from 'calif.io' for the report. + +(cherry picked from commit a587535c5dd8a5ea8259507152f055be318367df) + +CVE: CVE-2026-32792 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/a587535c5dd8a5ea8259507152f055be318367df] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + dnscrypt/dnscrypt.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/dnscrypt/dnscrypt.c b/dnscrypt/dnscrypt.c +index 4902447fd..173484cdf 100644 +--- a/dnscrypt/dnscrypt.c ++++ b/dnscrypt/dnscrypt.c +@@ -361,7 +361,7 @@ dnscrypt_server_uncurve(struct dnsc_env* env, + + len -= DNSCRYPT_QUERY_HEADER_SIZE; + +- while (*sldns_buffer_at(buffer, --len) == 0) ++ while (len>0 && *sldns_buffer_at(buffer, --len) == 0) + ; + + if (*sldns_buffer_at(buffer, len) != 0x80) { diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 3adc98621e..1225cb99c2 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -15,6 +15,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42944-1.patch \ file://CVE-2026-42944-2.patch \ file://CVE-2026-42959.patch \ + file://CVE-2026-32792.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:05 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97896 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 12FDDC88E41 for ; Thu, 10 Sep 2026 23:10:07 +0000 (UTC) Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27834.1789081800654449780 for ; Thu, 10 Sep 2026 16:10:00 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=sRGGUMdp; spf=pass (domain: gmail.com, ip: 209.85.216.46, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-38e42560ebcso290800a91.1 for ; Thu, 10 Sep 2026 16:10:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081800; x=1789686600; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ar7uUfQa5gC71YYexyU3oxDlWFhuLtKKDzqgATvwLVQ=; b=sRGGUMdpQl4GD3rD4HtUoTkaYg2TmgTeUyNcflyllV2E5T0eWH+uqrHDmynGuP5Yda U28agp/w2w22gAg7iUK8RzEkTOFq6N6B9xxqOkxFfj2u1NBA+3621kE8fY/NF4X/7XRg mIuPak1XaRpUQ9slWUekXdo622pt0qZxh8lVPBJbPI8hxHu4UJZH3C5UTIJ3xn5wRsA1 pz4mS3fDMalo5Q2x6aojiNv8yVhEX1TDiLMQaqvNej2eJG733TJckq0uBxqYLJ14IUts CWckYb9d5cpkvt1wuqkAVdP7+A9iVUbmvGknbTg8v26EWPVVAqFxdUKfN0hL7YRERPTB ctFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081800; x=1789686600; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ar7uUfQa5gC71YYexyU3oxDlWFhuLtKKDzqgATvwLVQ=; b=JotFetP8UpaNDblnCGyvua4s2gKxfbR+X241kDng1/u/00+fKrYW8LI3BFL/tbaFXH wyVzeGjPABLfeaC4YDrHJi8S/w4DIYrJqbZh0LG2jDCrVyri/kvqA1kR+YqmpitxV55E iR5KHlJffPQlbt2tk1pNpIV4gkiY/FqMktA2ngBQbTLUe2g4PWwkrYBx82zNQNUfua6b aiHansKlQ6BJZ/xZqpKVU6dvy80yjXsUzLwO20UbF/clmKOg5/YJd1QbzUEc+FVUuYAY azinUWdvuBw0wYx3DBerp5eHOoJXIpOFM/32g96A0YELT9vS0pNw8YS9qJArN8xG93VX GqVg== X-Gm-Message-State: AFuF++lrRWDsVp9o5bbkMmhXQym/Sf3mOZoXSe4TcSfw49y8PJxljIzA BptH7E6rKV62dY3CZ5DU+/JCNaA1/eczBU70lMGLnF0KKPwxPDGk8iHVX9pWCg== X-Gm-Gg: AYBFou2vABzKTxyt6QE6c8z598Fiun7R3eMjBw+4ub5xis59eHiowJ4PgOcn+wD7ED5 N25zff/RRuZw2ce2sf7OoYFg43tniG5HJEI/Sfg931L58gknDf3nQJcM1aTQFwuJ0+wvmQnke6S 4OQmyYYr4k3q9MEhiouZpzif5Uifk7uVnsD7dDXq5dccBAvxvX0rRH/iRoxOyS7917XFhrVIcF7 T9kKdlaMhUrLogbWAwGJ8jzf0DdO4qnadOtoA0MBDDeqiQVMPwDUcqPzakLoxJctnLJxpckZ8Kj 0KJh3a3IJpC1KJEID32yZa2ORgWK9An0yYuOXeaFXb2eNzSxqZMb135AanL5yDOImFGVxSmwK5N I5tKxXt26LR5jyNwcT7lqhEgS5rc0UNTZ47lkyPnJcrIE3+6pwWIQkGHd0JPgx0PRI/+Q6/8ax5 +OwINuSHDym+Ihl6w9c3SNVoeFs4Sixtd55LGpXaUo1l1yGjuDF+6JkeOrEWdWFKRgdE5X24oRq lYDwn3cmJRuJzQUhIusWj4= X-Received: by 2002:a17:90b:39a7:b0:398:9bd1:3214 with SMTP id 98e67ed59e1d1-39d9c223eb3mr1724755a91.21.1789081799938; Thu, 10 Sep 2026 16:09:59 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.09.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:09:59 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 6/32] unbound: patch CVE-2026-40622 Date: Fri, 11 Sep 2026 11:09:05 +1200 Message-ID: <20260910230932.173913-6-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129924 From: Ankur Tyagi Also backport TTL_IS_EXPIRED macro introduced by commit: https://github.com/NLnetLabs/unbound/commit/73e408f1d0792267429e9f5f89537cda61297952 Details: https://nvd.nist.gov/vuln/detail/cve-2026-40622 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-40622.patch | 58 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 59 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-40622.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-40622.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-40622.patch new file mode 100644 index 0000000000..1e338b1709 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-40622.patch @@ -0,0 +1,58 @@ +From 8711cb40328a6fab85bebb12be0c2948c0752291 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:16:18 +0200 +Subject: [PATCH] - Fix CVE-2026-40622, "Ghost domain name" variant. Thanks to + Qifan Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit 8d8fa4226613138f5a244a9f1a2506704e049180) + +CVE: CVE-2026-40622 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/8d8fa4226613138f5a244a9f1a2506704e049180] + +Dropped changes to the Changelog file. + +Also backport TTL_IS_EXPIRED macro introduced by commit: +https://github.com/NLnetLabs/unbound/commit/73e408f1d0792267429e9f5f89537cda61297952 + +Signed-off-by: Ankur Tyagi +--- + services/cache/rrset.c | 10 ++++++++++ + util/data/msgparse.h | 4 ++++ + 2 files changed, 14 insertions(+) + +diff --git a/services/cache/rrset.c b/services/cache/rrset.c +index 6d5c24f80..81f4e2820 100644 +--- a/services/cache/rrset.c ++++ b/services/cache/rrset.c +@@ -149,6 +149,16 @@ need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns) + if(equal && cached->ttl >= timenow && + cached->security == sec_status_bogus) + return 0; ++ /* ghost-domain: never let an NS overwrite extend lifetime ++ * past the entry it replaces, regardless of trust. */ ++ if(ns && !TTL_IS_EXPIRED(cached->ttl, timenow) && ++ newd->ttl > cached->ttl) { ++ size_t i; ++ newd->ttl = cached->ttl; ++ for(i=0; i<(newd->count+newd->rrsig_count); i++) ++ if(newd->rr_ttl[i] > newd->ttl) ++ newd->rr_ttl[i] = newd->ttl; ++ } + return 1; + } + /* o item in cache has expired */ +diff --git a/util/data/msgparse.h b/util/data/msgparse.h +index 7de4e394f..9bfe0225d 100644 +--- a/util/data/msgparse.h ++++ b/util/data/msgparse.h +@@ -98,6 +98,10 @@ extern time_t SERVE_EXPIRED_REPLY_TTL; + /** If we serve the original TTL or decrementing TTLs */ + extern int SERVE_ORIGINAL_TTL; + ++/** Check if TTL is expired. 0 TTL is considered expired. ++ * Used mainly to identify parts of the code that do this comparison. */ ++#define TTL_IS_EXPIRED(ttl, now) ((ttl) <= (now)) ++ + /** + * Data stored in scratch pad memory during parsing. + * Stores the data that will enter into the msgreply and packet result. diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 1225cb99c2..1c9a7fa489 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -16,6 +16,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42944-2.patch \ file://CVE-2026-42959.patch \ file://CVE-2026-32792.patch \ + file://CVE-2026-40622.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:06 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97898 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2026DC88E45 for ; Thu, 10 Sep 2026 23:10:07 +0000 (UTC) Received: from mail-pj1-f42.google.com (mail-pj1-f42.google.com [209.85.216.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27835.1789081804596741523 for ; Thu, 10 Sep 2026 16:10:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Z1Kgi0wt; spf=pass (domain: gmail.com, ip: 209.85.216.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f42.google.com with SMTP id 98e67ed59e1d1-38ec1402b05so273040a91.2 for ; Thu, 10 Sep 2026 16:10:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081804; x=1789686604; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XgA1xrq578t5HSQKvEAHraUaSA9gmzb+lHrdv60mZec=; b=Z1Kgi0wtC3IhmJyZi3vmh4Rh5Eyh4pPWrHooDJZsiscyvpCan6jCYmWwnSLQyUknSg guIjzybWThbe1MOpYN/ZQ0j4FlPmRcpVRq26J1w2P6Lu73vJtJpuT6vuLNkWZ4Hu0haT B2TIqst1VAw2bmZ20hQfqJzqE128uKPDDmFYn8twrcttC30nu59DTYqYtlYyxaKIDg6y 27upblW611esam3EHImLZDOe57QpUT+XCDcPWdQB3E0H6N24osHFgmjSZTg9k4AsSDyZ mz0vTNxtFn6/a4DyhcE686PFmevqhISSH1QopPOfV0T1vKpOo9SXhnwaAYkUZZLlohjH usAg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081804; x=1789686604; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=XgA1xrq578t5HSQKvEAHraUaSA9gmzb+lHrdv60mZec=; b=Wv85TeknztWg6hvQdqRjTIgXt2xrqdaHCpOhDESzUQGiZHbNCPFWDhxAOFpd3ivhlZ PDBhQx9MxBpmnuWzSDCrcHCYtkGgX+3s17ScqMWsDsNDNDXyXQUS4vsMy1M4x3pHDcdZ Vp89lRsi0sdPD3nhg+IEBHjJkqWCTwulIyrVMMPY2G+wAb56LIO2YZfpQfkkiUCofwLo NZ2QrgtGAF0ra3MCXd5VrbBVuoY83rd6IcXU5qxVeEbjUUC3Qa2BBAoXzO31Vg6uqd+p krfEqw0lHf2k6k5jXSuw5Y1HsH/NPURrKjT4jv2tug6iJbBVokqgho4QUUv16faxBlJr mYdw== X-Gm-Message-State: AFuF++mWpj2OxDe2BcNAhJA+J1hDhujz1Mui/hV9rSVYO2bYqcdjB5h4 8OIREKqyoxPNTgjZL0MuW5WdalGroSrUUdpuGaNTvtoymImD5qLHPheCLLszkw== X-Gm-Gg: AYBFou1mUxPM00R1vN45Ml70AV30XT4Ivt7s554ZXq2vqgyK6IretbNx3KkGkp5Gn8J c0Qg5ILPynYZOi2s6kdnn0KT2dSH0W0BUvNqQuOW3/tyhdUePpyATxmCQBwFefFKpyvFdakDebs TqjoIH4eS0ubE/Ls2o1FjWKKiREvXrU8CDFo2yEQ775Tz9bRwFF8tLS4UPluC/TOmTeDuVsQKHP nyel+UNtyRPFKWYpdGYTnZgpHhtJCPC5DCmZtK+qpSyL6mcyrofwxZx7Op/bpVDiZdEKC/fR6+Q btHtmqN2ezigmKd1wylzKvhfQsS4QKais9RXPgrCYLfd3upXmX8NglfFFtZDDdjL0ao9HLGFY8m 8dhCHFleDo4/Y6X8inudg4Os/uixaK4w154B4Gd8X3uXxgYtamzd2lmq6pt3TrzTG90XMr99h7V DJXNlUwyMswvUVskKPJMvBH/e11vICliokqwGgVTtVEbM7sw7wNCav2HZzC7S3qdx8u6tp6pjdK S4o2kjMjFcBPpxW6V8cRIU= X-Received: by 2002:a17:90b:588d:b0:399:1f8b:d255 with SMTP id 98e67ed59e1d1-39d9bbc823fmr1805677a91.5.1789081803787; Thu, 10 Sep 2026 16:10:03 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:03 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 7/32] unbound: patch CVE-2026-41292 Date: Fri, 11 Sep 2026 11:09:06 +1200 Message-ID: <20260910230932.173913-7-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129925 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-41292 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-41292.patch | 83 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 84 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-41292.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-41292.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-41292.patch new file mode 100644 index 0000000000..8ca3ec2716 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-41292.patch @@ -0,0 +1,83 @@ +From 97caf75e44191118fcb678f95fca15d3ea2a074f Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:18:23 +0200 +Subject: [PATCH] - Fix CVE-2026-41292, Parsing a long list of incoming EDNS + options degrades performance. Thanks to GitHub user 'N0zoM1z0', also Qifan + Zhang from Palo Alto Networks, for the report. + +(cherry picked from commit ef5ca84360934fa1e857ebc371d4b093aea6355d) + +CVE: CVE-2026-41292 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/ef5ca84360934fa1e857ebc371d4b093aea6355d] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + util/data/msgparse.c | 11 ++++++++--- + 1 file changed, 8 insertions(+), 3 deletions(-) + +diff --git a/util/data/msgparse.c b/util/data/msgparse.c +index 2d0955631..169709b7e 100644 +--- a/util/data/msgparse.c ++++ b/util/data/msgparse.c +@@ -53,6 +53,8 @@ + #include "sldns/parseutil.h" + #include "sldns/wire2str.h" + ++#define MAX_PARSED_EDNS_OPTIONS 100 ++ + /** smart comparison of (compressed, valid) dnames from packet */ + static int + smart_compare(sldns_buffer* pkt, uint8_t* dnow, +@@ -950,7 +952,7 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + struct comm_reply* repinfo, uint32_t now, struct regional* region, + struct cookie_secrets* cookie_secrets) + { +- int nsid_seen = 0, cookie_seen = 0, padding_seen = 0; ++ int i = 0, nsid_seen = 0, cookie_seen = 0, padding_seen = 0; + /* To respond with a Keepalive option, the client connection must have + * received one message with a TCP Keepalive EDNS option, and that + * option must have 0 length data. Subsequent messages sent on that +@@ -970,7 +972,7 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + + /* while still more options, and have code+len to read */ + /* ignores partial content (i.e. rdata len 3) */ +- while(rdata_len >= 4) { ++ while(rdata_len >= 4 && i < MAX_PARSED_EDNS_OPTIONS) { + uint16_t opt_code = sldns_read_uint16(rdata_ptr); + uint16_t opt_len = sldns_read_uint16(rdata_ptr+2); + uint8_t server_cookie[40]; +@@ -1150,6 +1152,7 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + } + rdata_ptr += opt_len; + rdata_len -= opt_len; ++ i++; + } + return LDNS_RCODE_NOERROR; + } +@@ -1164,6 +1167,7 @@ parse_extract_edns_from_response_msg(struct msg_parse* msg, + struct rrset_parse* found_prev = 0; + size_t rdata_len; + uint8_t* rdata_ptr; ++ int i = 0; + /* since the class encodes the UDP size, we cannot use hash table to + * find the EDNS OPT record. Scan the packet. */ + while(rrset) { +@@ -1223,7 +1227,7 @@ parse_extract_edns_from_response_msg(struct msg_parse* msg, + + /* while still more options, and have code+len to read */ + /* ignores partial content (i.e. rdata len 3) */ +- while(rdata_len >= 4) { ++ while(rdata_len >= 4 && i < MAX_PARSED_EDNS_OPTIONS) { + uint16_t opt_code = sldns_read_uint16(rdata_ptr); + uint16_t opt_len = sldns_read_uint16(rdata_ptr+2); + rdata_ptr += 4; +@@ -1238,6 +1242,7 @@ parse_extract_edns_from_response_msg(struct msg_parse* msg, + } + rdata_ptr += opt_len; + rdata_len -= opt_len; ++ i++; + } + /* ignore rrsigs */ + return LDNS_RCODE_NOERROR; diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 1c9a7fa489..0688b8a78b 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -17,6 +17,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42959.patch \ file://CVE-2026-32792.patch \ file://CVE-2026-40622.patch \ + file://CVE-2026-41292.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:07 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97900 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A618C88E45 for ; Thu, 10 Sep 2026 23:10:17 +0000 (UTC) Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27769.1789081807045520619 for ; Thu, 10 Sep 2026 16:10:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=eiAI/ITk; spf=pass (domain: gmail.com, ip: 209.85.216.50, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-38ec1402b05so273065a91.2 for ; Thu, 10 Sep 2026 16:10:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081806; x=1789686606; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PMg1QvjicNk6sI4BgB2PpkhYAuG7UZe4JrKGOptw888=; b=eiAI/ITk6wVmCVWUEX5q80nSdckz9C6kdQwvCCDLsRfHl79u+zoldwrZ6QyRUbAg/m jGJqToN30GNCb5mUxf2PIpSzFEapXZ0x+WMU4bPX4HmR2GE+hTT+7yU2dX/rt+eqDppP q+qqL32b6TZOPhJNUrr32HND2gjDJzIkNCgFVh+jRdZ0wjQAacch2ez45Kri+efpn8Vk hLMf2bil3j1UuJqktlPmCY8Wa1y+WG+rpofGoNUQzHG7FMcvOHeHBG7UqWgvZZIQO7SO WYudlKcOYNR6JhptPBSO4Qiew55lFdSyZ2+R8hQczUZw0MHdPFJxWX1gg8az6/702Ao3 m3Ow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081806; x=1789686606; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PMg1QvjicNk6sI4BgB2PpkhYAuG7UZe4JrKGOptw888=; b=W6Bozas3B4vLoMKN5lGqRX7DrZ1Bu2HkEwpBtJ82gMAmDNUIRlprbQzkP2QHkCngBc fAgxGuHeQJDzpIibR1VbccVpjtMd9+3ep9+UIC4Y6kM5wcMVGilqhk0qvNM1a/AVqO9R gI+EQZUPSLyvpV0DrYHJWi6co7miOvvy4B7AbhWBQLEFPW0U/CZWdi6piM8nvFiP9vvl KvvgpnA95IhS7ohgAbOFoS2h9iy3Ww3EE5DVik92JZM5zNCorPbP3s5F8M10xk6ffA4G uJ3LSn65Cxbbo7UachwUZnHD+QG4I9iUQqgkd6GAJTjyRKMd2/9zX/qCx7tzrDoZgwQF HEwA== X-Gm-Message-State: AFuF++kgrOr5zYx36B5iXELjJ7hD2VL6OiR25QWdO22MSlGF8O1gMHx4 yTUkd0PbMmCnjYzPA+AWGFYujgxWka+GacU78CPxkFChHst2gvN76NhyLgRfJA== X-Gm-Gg: AYBFou3sZeqIDsVQJreGCXX+Wz9GfhP1kuX6zbzrrK+0HiN0xO5XfsTWh4jI3mCccQS oYgRsMxSwwdvni/VNZmuBvhNsKJFh7+SaYttLSorV86GTZoUicURByUJZ/Cl93d8fqzNXIuif53 Ci4QeLv6S7zn2bug6ZNq9coOVp/Q4gWvb+arOvWHwXGN+6fpCsDvfKoWIr3pQQc/82oClA9f419 uQkRWDZNJalnEUkHTAxbp9jS+gjrtVViWBxH6jncsSFsRzDjyeOu5BPfoxnewvUcjr/a79EeQZw H0wqOF6cC7vINL41Zd4QZsk4jlbsTVUUpQb6pQfPYhADR4G8O10qF0Kw+JJiERi1Sbor3HuLEqv mlf7/EpiMaVCEaj/eW85bvOoD1ba2eg0F6+mw1k50FARr+KOfL7G4GKoZqxPL26gt7HT7djziEw RKN/XgfbDJqjcpIH9eiNJcI0c9gosdFkzv71dUfS9mK3W1BbD/FuDJHyzUmiLdlxdS+ABndtH7m k82ZaEh4NooiJ6PwfLpxpo= X-Received: by 2002:a17:90b:5887:b0:38e:524:8797 with SMTP id 98e67ed59e1d1-39d9c1b60damr1594668a91.13.1789081806381; Thu, 10 Sep 2026 16:10:06 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:06 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 8/32] unbound: patch CVE-2026-42534 Date: Fri, 11 Sep 2026 11:09:07 +1200 Message-ID: <20260910230932.173913-8-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129926 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-42534 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-42534.patch | 70 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 71 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-42534.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-42534.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42534.patch new file mode 100644 index 0000000000..aed793ec5c --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42534.patch @@ -0,0 +1,70 @@ +From 0d649a36fd3c47f1b75ca90ce10e52cb4ae3d253 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:19:08 +0200 +Subject: [PATCH] - Fix CVE-2026-42534, Jostle logic bypass degrades resolution + performance. Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit a794c87578c963606a6fb00a54c46fcf935f519a) + +CVE: CVE-2026-42534 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/a794c87578c963606a6fb00a54c46fcf935f519a] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + services/mesh.c | 14 ++++++++++---- + services/mesh.h | 6 ++++++ + 2 files changed, 16 insertions(+), 4 deletions(-) + +diff --git a/services/mesh.c b/services/mesh.c +index 3212a6abf..23499dcef 100644 +--- a/services/mesh.c ++++ b/services/mesh.c +@@ -296,12 +296,14 @@ int mesh_make_new_space(struct mesh_area* mesh, sldns_buffer* qbuf) + if(mesh->num_reply_states < mesh->max_reply_states) + return 1; + /* try to kick out a jostle-list item */ +- if(m && m->reply_list && m->list_select == mesh_jostle_list) { ++ if(m && m->list_select == mesh_jostle_list) { + /* how old is it? */ + struct timeval age; +- timeval_subtract(&age, mesh->env->now_tv, +- &m->reply_list->start_time); +- if(timeval_smaller(&mesh->jostle_max, &age)) { ++ if(m->has_first_reply_time) ++ timeval_subtract(&age, mesh->env->now_tv, ++ &m->first_reply_time); ++ if(!m->has_first_reply_time || ++ timeval_smaller(&mesh->jostle_max, &age)) { + /* its a goner */ + log_nametypeclass(VERB_ALGO, "query jostled out to " + "make space for a new one", +@@ -1960,6 +1962,10 @@ int mesh_state_add_reply(struct mesh_state* s, struct edns_data* edns, + r->qid = qid; + r->qflags = qflags; + r->start_time = *s->s.env->now_tv; ++ if(s->reply_list == NULL && !s->has_first_reply_time) { ++ s->first_reply_time = r->start_time; ++ s->has_first_reply_time = 1; ++ } + r->next = s->reply_list; + r->qname = regional_alloc_init(s->s.region, qinfo->qname, + s->s.qinfo.qname_len); +diff --git a/services/mesh.h b/services/mesh.h +index f19f423a8..a61f90993 100644 +--- a/services/mesh.h ++++ b/services/mesh.h +@@ -189,6 +189,12 @@ struct mesh_state { + struct module_qstate s; + /** the list of replies to clients for the results */ + struct mesh_reply* reply_list; ++ /** if it has a first reply time */ ++ int has_first_reply_time; ++ /** wall-clock time the first client reply was attached; ++ * used by mesh_make_new_space() so duplicate retransmits ++ * cannot reset jostle aging. */ ++ struct timeval first_reply_time; + /** the list of callbacks for the results */ + struct mesh_cb* cb_list; + /** set of superstates (that want this state's result) diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 0688b8a78b..a70ae4c9a3 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -18,6 +18,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-32792.patch \ file://CVE-2026-40622.patch \ file://CVE-2026-41292.patch \ + file://CVE-2026-42534.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:08 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97902 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 29737C79FBB for ; Thu, 10 Sep 2026 23:10:17 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27770.1789081810100987718 for ; Thu, 10 Sep 2026 16:10:10 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=BsDGGdx2; spf=pass (domain: gmail.com, ip: 74.125.227.140, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj2-f12.google.com with SMTP id d9443c01a7336-2d8fb334ddcso2018635ad.0 for ; Thu, 10 Sep 2026 16:10:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081809; x=1789686609; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dbzAs8rwTYhZrNZD6M3foHBn1uW5DAPnaeRxeK0eI2M=; b=BsDGGdx2W0r+f2dBrkaz1khFSXztcUeueQVLRDwOhtwjZvpW4m7ClhVkil1nOJsSDA 0hZiAwpbFGYjwurjmWx6MGxf5msrUn2JzeZFuUGjcuhUn1+pdLALLwtsZ3JX4zKasJ2v unP60U4LskEwmuKZkjMA1f55CJtRo+3oPXswujLa8m3XOQnDLBQkf2XfqSuKIpwHMsBV XyNjVkFpoJZ94jFxUXdB98FWmgAS5yW0XcCoLeoSO2N+dsw1M0hagn+KgKftJ3Ek1RY7 JLpTwVAJhaRvphpjUMKfRg+pi8MPsIttESTqwzo6G78k3IJOAr3aeFhI9TlBI4QFjnxB NXhg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081809; x=1789686609; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dbzAs8rwTYhZrNZD6M3foHBn1uW5DAPnaeRxeK0eI2M=; b=CYXlLv3uKCfpKIpVC+25J6aRMJN/hr5qQ323Al5aNhPxbkGIall55X6OVkP9s5Gdi1 SqCMo3lz4lBc/vhgfEKpqxB59dQ2YIotnbWsz3ZhtUjHBRypxaoSutmj4pzxhj57ZPiH 1yimI/BcZxD1+BjIT0C6huhZEOMKnxlIlu2+2srybWrTkZHAt4nTA1E23w5Lx0PfjRqI BApNb3sDKkstgKvx2Rd8HV4naP92Vfj1jcy6Z5UGHDwtukzvSm/sC0bgayATXjS5Vebz RKaGuWxelcmpDo6fgOL7+aLNavr6uWySEECl2Ai6dRlbRI9hzzbV3mNehOhdqAJuXd+E VNPA== X-Gm-Message-State: AFuF++mlxKptHX8Su3GwdX11/aoFP/20MGOWX4DuZ5kJwbgf1FW72C9F 5okok4KS74d/AB8Zv19YpIaNbqNkUJ+zdup4FASMtXYDf5zXShJd80gyrnvmVw== X-Gm-Gg: AYBFou03YhnUAb7gczzKMDVtZvMITIFTaSIGgrjO2KGcppoNreRP0lfT2Kdr8yIyptc CZx8t7tRYdtapfmSQUJe+8kCrHeetkSD0QfVkZwH9ezCSYPebVqgva8esNQWTD1PV1VUMxiZ/50 HvBc+ezd1wUt5OLTQJO4gAuiW9iXoDcC6YxBhEPI6qcXxXUGdNMPLF80nenFl7pFTB3ExZoiFql klIY+qC1N5swP35I16PSTJrqIIDt2al8LRNozveV7MqMVF1GQIzj4EJRgJqAcoEQypvSq9rK86V 3AOdK7gWvmZkISAo+abdG4oj2g7gSaO/cVvfK+ZB/+zYK3/vZ2fyEGvLb91FoWxo7c35vzwSv9k jh37kcb6jHwzrI8eTpfL/Xppz8jo17wfHQI48Zs+EvswmVI1H9S9vU1NyCptynvWyHMJjrQZ8eT f+KBKo+K20ZWaGHj/rfyGEfRcPqIxWL+oxHK3LOBZnl4S4Gkl2/UNAKtPd21uG96IWO68yzX1Ot V4sg7tmjXPdSelbsJP9taWCXsYFPioBag== X-Received: by 2002:a17:90b:5246:b0:398:d2a0:87ff with SMTP id 98e67ed59e1d1-39d9bc67660mr1889870a91.1.1789081809377; Thu, 10 Sep 2026 16:10:09 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:08 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 9/32] unbound: patch CVE-2026-42923 Date: Fri, 11 Sep 2026 11:09:08 +1200 Message-ID: <20260910230932.173913-9-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129927 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-42923 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-42923.patch | 114 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 115 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-42923.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-42923.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42923.patch new file mode 100644 index 0000000000..da46770183 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42923.patch @@ -0,0 +1,114 @@ +From 7a2457c979cdc1f0c1bb1fe68010fdd2f46398f2 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:20:02 +0200 +Subject: [PATCH] - Fix CVE-2026-42923, Degradation of service with unbounded + NSEC3 hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for + the report. + +(cherry picked from commit c343fff3a4de922835fec7232b90faed658b5371) + +CVE: CVE-2026-42923 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/c343fff3a4de922835fec7232b90faed658b5371] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + validator/val_neg.c | 28 +++++++++++++++++++++++++++- + validator/val_nsec3.c | 5 ----- + validator/val_nsec3.h | 6 ++++++ + 3 files changed, 33 insertions(+), 6 deletions(-) + +diff --git a/validator/val_neg.c b/validator/val_neg.c +index bc3a83aeb..0f2751121 100644 +--- a/validator/val_neg.c ++++ b/validator/val_neg.c +@@ -62,6 +62,13 @@ + #include "sldns/rrdef.h" + #include "sldns/sbuffer.h" + ++/** ++ * The maximum salt length that the negative cache is willing to use. ++ * Larger salt increases the computation time, while recommendations are ++ * for zero salt length for zones. ++ */ ++#define MAX_SALT_LENGTH 64 ++ + int val_neg_data_compare(const void* a, const void* b) + { + struct val_neg_data* x = (struct val_neg_data*)a; +@@ -826,7 +833,11 @@ void neg_insert_data(struct val_neg_cache* neg, + (slen != 0 && zone->nsec3_salt && s + && memcmp(zone->nsec3_salt, s, slen) != 0))) { + +- if(slen > 0) { ++ if(slen > MAX_SALT_LENGTH) { ++ /* RFC 9276 s3.1: operators SHOULD NOT use a salt; large ++ * salts inflate per-hash block count. Decline to cache. */ ++ return; ++ } else if(slen > 0) { + uint8_t* sa = memdup(s, slen); + if(sa) { + free(zone->nsec3_salt); +@@ -1169,6 +1180,15 @@ neg_find_nsec3_ce(struct val_neg_zone* zone, uint8_t* qname, size_t qname_len, + uint8_t hashce[NSEC3_SHA_LEN]; + uint8_t b32[257]; + size_t celen, b32len; ++ int hashmax = MAX_NSEC3_CALCULATIONS; ++ if(qlabs > hashmax) { ++ /* strip leading labels so the walk costs at most ++ * MAX_NSEC3_CALCULATIONS hashes, mirroring val_nsec3.c */ ++ while(qlabs > hashmax) { ++ dname_remove_label(&qname, &qname_len); ++ qlabs--; ++ } ++ } + + *nclen = 0; + while(qlabs > 0) { +@@ -1269,6 +1289,12 @@ neg_nsec3_proof_ds(struct val_neg_zone* zone, uint8_t* qname, size_t qname_len, + if(!zone->nsec3_hash) + return NULL; /* not nsec3 zone */ + ++ if(!topname && qlabs > zone->labs + 1) ++ return NULL; /* iterator caller; opt-out proof would be discarded ++ * at the !topname check below anyway. ++ * The qlabs check allows the exact-match for ++ * the one-label-below-zone case. */ ++ + if(!(data=neg_find_nsec3_ce(zone, qname, qname_len, qlabs, buf, + hashnc, &nclen))) { + return NULL; +diff --git a/validator/val_nsec3.c b/validator/val_nsec3.c +index 92d853825..62effde20 100644 +--- a/validator/val_nsec3.c ++++ b/validator/val_nsec3.c +@@ -59,11 +59,6 @@ + #include "sldns/sbuffer.h" + #include "util/config_file.h" + +-/** +- * Max number of NSEC3 calculations at once, suspend query for later. +- * 8 is low enough and allows for cases where multiple proofs are needed. +- */ +-#define MAX_NSEC3_CALCULATIONS 8 + /** + * When all allowed NSEC3 calculations at once resulted in error treat as + * bogus. NSEC3 hash errors are not cached and this helps breaks loops with +diff --git a/validator/val_nsec3.h b/validator/val_nsec3.h +index f668a270f..a13e92991 100644 +--- a/validator/val_nsec3.h ++++ b/validator/val_nsec3.h +@@ -98,6 +98,12 @@ struct sldns_buffer; + /** The SHA1 hash algorithm for NSEC3 */ + #define NSEC3_HASH_SHA1 0x01 + ++/** ++ * Max number of NSEC3 calculations at once, suspend query for later. ++ * 8 is low enough and allows for cases where multiple proofs are needed. ++ */ ++#define MAX_NSEC3_CALCULATIONS 8 ++ + /** + * Cache table for NSEC3 hashes. + * It keeps a *pointer* to the region its items are allocated. diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index a70ae4c9a3..7ed5769c69 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -19,6 +19,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-40622.patch \ file://CVE-2026-41292.patch \ file://CVE-2026-42534.patch \ + file://CVE-2026-42923.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97901 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3F106C88E46 for ; Thu, 10 Sep 2026 23:10:17 +0000 (UTC) Received: from mail-pj1-f42.google.com (mail-pj1-f42.google.com [209.85.216.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27840.1789081812644360060 for ; Thu, 10 Sep 2026 16:10:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=GW3B9gmW; spf=pass (domain: gmail.com, ip: 209.85.216.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f42.google.com with SMTP id 98e67ed59e1d1-3964e480f76so402987a91.1 for ; Thu, 10 Sep 2026 16:10:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081812; x=1789686612; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=bDVXUsglM1KOn/EeGmIAM3JIq4RbfNX6aIBEEc5tpWk=; b=GW3B9gmWstBd+EjTgg7XeWBPEkeYWEGl1Dl93iWHDb0KHkVbiafxhYdJjhhuv7L/jL NHyxsfOI7kBJ4qHi2yY9AlhYVR7WxMUyDaSV8xso6Ph/07hMAcFVwtOjfdCmKhc5MqvW BubvfA2reEdx2zzsLOw8bFX3tx2/g3y0SYA109TA5KtUieqHubUktjx4aeC6HQfa6Ac3 cQYYKvhRXS9gMgkgMqCix30Pz+MPF2UG/MwmQHOGM+wze092qLdY/JOtowIMxnp9otg7 KBHyiOCYQDNOu5BAFQvcZp+IEh9VDPtg/cQ4W5H+isBs1uBu3S0iNSBrf+YhO3Bazztj MZUw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081812; x=1789686612; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=bDVXUsglM1KOn/EeGmIAM3JIq4RbfNX6aIBEEc5tpWk=; b=PoCSbc0zuTQit4yz0jgPBOLp/JQQyUl7PeUKMBwc36Q4PTkrwKOaQwb9hq4715B9X8 PfB5ZJDSnVQuEDGbBjNn7mXquxFk+M+3fySZpiZu1cMPpYRYfRgj+GFSFGyD+dXdAV1R yrsPslJZja+tXvhLHz+II1W2aHJ5rfmNplRB9YN/hKjXu5QYEiCc0SJ9bzqEBE1EWvNM 9L4n6SRp7rHJI5UxlEd6gf/atdYi7FIO61rLWRZL4TNe24/T0m02YN81yS0iX6g0pvO8 3Eud/120v7CS05dV90S7oaAXAjhJsnUzeDEBUBFiXXFx+bamT64QJ6h0i1x+q+bZBjMM 5dJQ== X-Gm-Message-State: AFuF++nOtKX5D7R0mCzfrDa6Fn4UHAeQNN5Bu8zm0WSrzS8ozWp7eQTk 699Vrg9KgSss9AAn5cbUwV7J3BybG58roYyAo2Z0MhqGR4d9BkBk2BDxmP+Y/w== X-Gm-Gg: AYBFou0AElT1w2zY9U73Eb9kaBz6i8jdXFSLiSx345gQtIerqXd23exfmwaqi1ASYH8 Fe0ATNrtztyX0s8U9Z3Cm5yXOoM0H4GzUn+gOf+Kehgb40A1ZIH4UP8eIuLChgUmv15UC2tgRyf hLdkm9WW9Wyzvt2OZMi9qV0AC7O8Nx+nDMnKy28I/n6cVhSsEXA812IHVNpgUhKzQRsCVuDAM1q RD6TNHAM8+hL0wTg4FaIqTACF1HUbTto+VDeJp7195yTk/qbd0ST7VgcNS1b5QqRSVeiWA+BLs0 h9luJYKWWV3tn1wYVnb9xj+0ccoIr1aBtzoUGf+vexUg8DyV7ySqm9Te1HtLgK3SQlcD6nXKmae 5mdiuMY7P2kEmhPbJzp05eyeEin1ulc1w3Y4wFxdehxc3cBnP0RHD18ugAwh0Y/QhfB3JwVgWia Z0lMORu3G6iZGPtTCVMfay7HOhudsEsiloiHjGjJw/LAi4NuU2CqIG960/RLkvFK+VuiVr74c2k ajJJ73WmptVEJniqzk3ca4= X-Received: by 2002:a17:90b:1d49:b0:398:9be5:b417 with SMTP id 98e67ed59e1d1-39d9c1fc96emr1718207a91.18.1789081811936; Thu, 10 Sep 2026 16:10:11 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:11 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 10/32] unbound: patch CVE-2026-42960 Date: Fri, 11 Sep 2026 11:09:09 +1200 Message-ID: <20260910230932.173913-10-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129928 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-42960 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-42960.patch | 38 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-42960.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-42960.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42960.patch new file mode 100644 index 0000000000..13f99d4803 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42960.patch @@ -0,0 +1,38 @@ +From 7bd2ccb4a490b95ee9e8297ebbcb8fec91d11859 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:20:45 +0200 +Subject: [PATCH] - Fix CVE-2026-42960, Possible cache poisoning attack while + following delegation. Thanks to TaoFei Guo from Peking University, Yang Luo + and JianJun Chen, Tsinghua University, for the report. + +(cherry picked from commit 8ae4b4545dccaaabd30b597b0dcb0d9640c8cc39) + +CVE: CVE-2026-42960 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/8ae4b4545dccaaabd30b597b0dcb0d9640c8cc39] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + iterator/iter_scrub.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/iterator/iter_scrub.c b/iterator/iter_scrub.c +index 8507a3fb6..852705db3 100644 +--- a/iterator/iter_scrub.c ++++ b/iterator/iter_scrub.c +@@ -725,7 +725,13 @@ scrub_normalize(sldns_buffer* pkt, struct msg_parse* msg, + rrset->rrset_all_next = NULL; + return 1; + } +- mark_additional_rrset(pkt, msg, rrset); ++ /* Only mark glue as allowed for type NS in the authority ++ * section. Other RR types do not get glue for them, it ++ * is allowed from the answer section, but not authority ++ * so that a message can not have address records cached ++ * as a side effect to the query. */ ++ if(rrset->type==LDNS_RR_TYPE_NS) ++ mark_additional_rrset(pkt, msg, rrset); + prev = rrset; + rrset = rrset->rrset_all_next; + } diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 7ed5769c69..a6f9b14cab 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -20,6 +20,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-41292.patch \ file://CVE-2026-42534.patch \ file://CVE-2026-42923.patch \ + file://CVE-2026-42960.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:10 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97899 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A5BFC88E41 for ; Thu, 10 Sep 2026 23:10:17 +0000 (UTC) Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27773.1789081815417016519 for ; Thu, 10 Sep 2026 16:10:15 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=i4hwy8Gz; spf=pass (domain: gmail.com, ip: 209.85.216.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-39682983a0fso329873a91.3 for ; Thu, 10 Sep 2026 16:10:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081815; x=1789686615; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5VlGPuLG7rXCC+OJbukjX+gyGDPg8GSNmQ7CaVyQwCc=; b=i4hwy8GzQrwSKKH9i8t2iiTuPq4ePqsuGNFMUVZUO8iTxsMMn9+plfwjbgKjTumaaz d3WbPFmW5N+wNKGK9E7eKvsA1KaGQgTi3DqkggDajui0O/xDRY8gxEelFX/fYnbhtiCb nK6YXjtZE6qhKsyfh3WASbICNVqLSgDjMzr886eVN7aaZnkJ8orpFjoYHYaXQIywO08n 68Qc5aP5CIaMPcFbcTgSUZwa38zE2seOdcS4G1NJ68vodf0Jz/Jz2LE5D7pb6851n3Gg PifjmojEH6YKXliW1ZNLHIOmkyCl6oAKzVQLkFHV6qDshpJ+gEcyL2/b+WiiPkB+Aj3U i9Wg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081815; x=1789686615; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5VlGPuLG7rXCC+OJbukjX+gyGDPg8GSNmQ7CaVyQwCc=; b=PrW7BTyVS0V0oxOiuInr3aD0ydx6KxXBl52a7N6s4d/zlC+noSuxp0l/xxgcGCJt+c 73OCtqhQ/orPHo8Z4ITO+I3iTKjX/9QquIha2ZzDYiZW+DgZhjC2vOg372V/PmbFXR7W oMapVomuB+a4YQRSsH/gUOhQSrhWKhyjYR4o8rac/UUWwJixS5MHXcfXazJhyP++PNcb 2h6akLcjBmpfQvqcn4Wv9YqkHAx6DKu6r9KEmdyRt57VIlhFTDadOYn9Lfb4mIzGfwqQ oV48Rh3BLwaxOmz8UxcwvPp8FrGQTGek/l0YFKpK6EQr4Xs5LSky3g2UYX3+E0x0MOR3 0rCA== X-Gm-Message-State: AFuF++lYD3ZIzMw+UW2bhQYPfNXg4a7OUhqiPBZw+T7wMYE3OG2X+8Oj 8TEZ5Mb8RdiPK0OymuscW294wrFA17UiN/ekG3EG2LthP44w1FRVO7+Mmyg1mg== X-Gm-Gg: AYBFou0bxBQy8PaTicpHDu2Z2SIkEz592p34Grr7EHhDxE95SsLFnshDwVq/p+GGxRI xqdmCSwIDEHdHz8fZ8HKjpNAhwDoXZUQKvZCCY0lFRU4BK2yxGHfuMp+QGQwIsea105VRM6XKzh qPlz8TfxokTvdbK+gXPOKv7Q/zLaN22oI/Ei+ILLGHE6rk9LIOCfHJj8kMqmFkHoBR81lJIXAh3 gIE7C1MLLY8MJna/1BLeQSKB5+fCUAx1cnlJX1+fBUd0rs3jjAN93e7l8tOWB+joSDq8BDM3MWo gtrIS0INS7/wRjP68dmzFJUXigY9yWdbHpqBmzDuo1fUzCbdhzuUBrS5qW7Z2LkluU/kx2Nz9Uz IVNxHj57AQrUpUPbwzpa+/peosbdqH/B91wXOMI54piUL4qFhhCzN9yLntKjre/fLLkEYqrTuBT odo0FGAyuTNXgAviKpBvf83wdJ0l1fy//zByERo4uWwo9HE3pmO5bShpjcdv7UsxsHVg4UaW5HD +8tXe0C3tpYRQeXs+hpQF1XIg== X-Received: by 2002:a17:90b:3c8d:b0:38f:de97:b06 with SMTP id 98e67ed59e1d1-39d9bbdbac7mr1865517a91.5.1789081814736; Thu, 10 Sep 2026 16:10:14 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:14 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 11/32] unbound: patch CVE-2026-44390 Date: Fri, 11 Sep 2026 11:09:10 +1200 Message-ID: <20260910230932.173913-11-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:17 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129929 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-44390 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-44390.patch | 37 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 38 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-44390.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-44390.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44390.patch new file mode 100644 index 0000000000..6c13e90bf0 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44390.patch @@ -0,0 +1,37 @@ +From 166c308b1beba4ecf586d51d63513478d75019a1 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:21:26 +0200 +Subject: [PATCH] - Fix CVE-2026-44390, Unbounded name compression in certain + cases causes degradation of service. Thanks to Qifan Zhang, Palo Alto + Networks, for the report. + +(cherry picked from commit dae7a3797424607906b132c008fc12dba867b5f3) + +CVE: CVE-2026-44390 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/dae7a3797424607906b132c008fc12dba867b5f3] + +Signed-off-by: Ankur Tyagi +--- + util/data/msgencode.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/util/data/msgencode.c b/util/data/msgencode.c +index 7bc55a54e..f84c491b1 100644 +--- a/util/data/msgencode.c ++++ b/util/data/msgencode.c +@@ -352,7 +352,6 @@ compress_any_dname(uint8_t* dname, sldns_buffer* pkt, int labs, + (p = compress_tree_lookup(tree, dname, labs, &insertpt))) { + if(!write_compressed_dname(pkt, dname, labs, p)) + return RETVAL_TRUNC; +- (*compress_count)++; + } else { + if(!dname_buffer_write(pkt, dname)) + return RETVAL_TRUNC; +@@ -360,6 +359,7 @@ compress_any_dname(uint8_t* dname, sldns_buffer* pkt, int labs, + if(*compress_count < MAX_COMPRESSION_PER_MESSAGE && + !compress_tree_store(dname, labs, pos, region, p, insertpt)) + return RETVAL_OUTMEM; ++ (*compress_count)++; + return RETVAL_OK; + } + diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index a6f9b14cab..9de6a3c88c 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -21,6 +21,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42534.patch \ file://CVE-2026-42923.patch \ file://CVE-2026-42960.patch \ + file://CVE-2026-44390.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:11 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97903 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 464E3C88E41 for ; Thu, 10 Sep 2026 23:10:27 +0000 (UTC) Received: from mail-pg1-f182.google.com (mail-pg1-f182.google.com [209.85.215.182]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27842.1789081818168625181 for ; Thu, 10 Sep 2026 16:10:18 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=j3LU8WCo; spf=pass (domain: gmail.com, ip: 209.85.215.182, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pg1-f182.google.com with SMTP id 41be03b00d2f7-cc439bfb2d8so321530a12.2 for ; Thu, 10 Sep 2026 16:10:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081817; x=1789686617; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GwV3ZagqPFoz/csPdas3ECH7LV6DAHYVZl4g/DpyLOI=; b=j3LU8WCo45/5vHDLi6LFsCO7HTaUcqXEMHmPJAEOc5QMV7+p/HejwscgGEr5zUPuwy XSbco0C9pqH8pBXzNDxzCnx1dz8Bf/iDSGhvmXgWPxxi07fikR+hiHY3NLA22H43zi3z BV4iXUXYZBr4q1tbOa1rs5IEECXo4XSS506cC6uFfLSoE8MHM0PkWjLA2qOG0FuSaNgK gnuLl2lmr3Pl6OgxFSqN3oCOhw1HBxEZxVOne1+xDe6JI0NwZ/1ouswsboVPzpKq84tq beZp1Hb/at73j8d9TOUxyKh81OCX8X37DtBdVEQjK+Y3T0Z3hVEIxGMDa7iqGXHB7H5C XdUw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081817; x=1789686617; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=GwV3ZagqPFoz/csPdas3ECH7LV6DAHYVZl4g/DpyLOI=; b=B+5PjmjXAWRIpgnE9G0GxbcGl9bv1XXYygIm15klH3CzBYXPmpAMEj0xiNHwiF+l4L rqnOK7sPrLsLvEL9XwBSdjHVUb87QdVL/keXUtt0ehiPmWelSJPu6K6vJJVB3LNonf5O vV3pgTextm0phQb1gSxTCsHnxxwxFVu/V9p5ib8Pdx7blOHS0Y02DBkPqTb08za33TYr r7LVJ8yB2tfi1tElpkQy/X2D3ENhyImulMTrQV4KPeq+/lzAV9t8A7ltI7dT2ZALL1hF SO7RrVIpp0gDOOzQuYwjDCgDoIhi51ms8Y17cGMhOz+tio1I5pRCtcHX/h35E3K4RBhn 6b8A== X-Gm-Message-State: AFuF++mijCz54bVmC8iBV6SSCweh+aeoTsgh266fX6d/0TrJQDi8856q 6olM+4RQgg0YVC/v2ekBfyp7qGGBqQjRBKBC6EIjA2drnaB+9/dqP27rSO5y4g== X-Gm-Gg: AYBFou03MjJrWF5f2ZqmiVXdmk961BCfwryiDuUF0s/stxEmqLOFIlPRp2nueW5xue0 8a4JBWwJcre59KtD9Y52tZb7E+2qOSodxO2bEAmCstGY26bHu4QzjJ0jynJBGxmf/N3DwTAfE0p qDYcMEN1UiDxfG+x4U5j12K2PUajQFru0FeI6MQ9sCpjgeljKOi4cJs4c1Nl94zsu3/EFv372Tc q1as1hE4DfAgLRgeLO26R5uM8PMm0E/AuvpQv3gNcGeT6FetN5unW8c+pftjiE3j5//ekQxPVhh uJct693WaV/QBXNzfGHSZGqrn5tGIn9kU5MxhrlWbwhWhjD2M9ePu8I2FtB2WSo0KyN0rHL0XjL X17T/ssvz8+Tlfv36eI95HEzX1JxZsa02udzm3KhvY4IsvRKgRWXvvgv+kdR+X9U4b6kswd8ktK aiOU2bMTmCJsi1YmGK0bPixzPv39zFrxOVxf2Nb5PXaM27fJDFOkF7sNPtp9cuil6GKrbTQXxZx S8z4QU4D9RJe657/6Nl7Rw= X-Received: by 2002:a17:90b:1d0c:b0:398:d292:e6d5 with SMTP id 98e67ed59e1d1-39d9c35972cmr1734220a91.24.1789081817359; Thu, 10 Sep 2026 16:10:17 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:17 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 12/32] unbound: patch CVE-2026-44608 Date: Fri, 11 Sep 2026 11:09:11 +1200 Message-ID: <20260910230932.173913-12-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129930 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-44608 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-44608.patch | 59 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 60 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-44608.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-44608.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44608.patch new file mode 100644 index 0000000000..0552804051 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44608.patch @@ -0,0 +1,59 @@ +From b70913c1208eda8494e2d6dd81910e92b8640dcc Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 20 May 2026 10:22:52 +0200 +Subject: [PATCH] - Fix CVE-2026-44608, Use after free and crash in RPZ code. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit 75b6dba593d4fff000434cd64807c6ebd50bd244) + +CVE: CVE-2026-44608 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/75b6dba593d4fff000434cd64807c6ebd50bd244] + +Dropped changes to the Changelog file. + +Signed-off-by: Ankur Tyagi +--- + services/rpz.c | 10 ++++++---- + 1 file changed, 6 insertions(+), 4 deletions(-) + +diff --git a/services/rpz.c b/services/rpz.c +index f45cf6542..27f7de861 100644 +--- a/services/rpz.c ++++ b/services/rpz.c +@@ -2468,6 +2468,7 @@ rpz_callback_from_iterator_module(struct module_qstate* ms, struct iter_qstate* + { + struct auth_zones* az; + struct auth_zone* a; ++ struct dns_msg* ret = NULL; + struct clientip_synthesized_rr* raddr = NULL; + struct rpz* r = NULL; + struct local_zone* z = NULL; +@@ -2511,13 +2512,11 @@ rpz_callback_from_iterator_module(struct module_qstate* ms, struct iter_qstate* + z = rpz_delegation_point_zone_lookup(is->dp, r->nsdname_zones, + is->qchase.qclass, &match); + if(z != NULL) { +- lock_rw_unlock(&a->lock); + break; + } + + raddr = rpz_delegation_point_ipbased_trigger_lookup(r, is); + if(raddr != NULL) { +- lock_rw_unlock(&a->lock); + break; + } + lock_rw_unlock(&a->lock); +@@ -2532,9 +2531,12 @@ rpz_callback_from_iterator_module(struct module_qstate* ms, struct iter_qstate* + if(z) { + lock_rw_unlock(&z->lock); + } +- return rpz_apply_nsip_trigger(ms, &is->qchase, r, raddr, a); ++ ret = rpz_apply_nsip_trigger(ms, &is->qchase, r, raddr, a); ++ } else { ++ ret = rpz_apply_nsdname_trigger(ms, &is->qchase, r, z, &match, a); + } +- return rpz_apply_nsdname_trigger(ms, &is->qchase, r, z, &match, a); ++ lock_rw_unlock(&a->lock); ++ return ret; + } + + struct dns_msg* rpz_callback_from_iterator_cname(struct module_qstate* ms, diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 9de6a3c88c..8bd8732fe4 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -22,6 +22,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42923.patch \ file://CVE-2026-42960.patch \ file://CVE-2026-44390.patch \ + file://CVE-2026-44608.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:12 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97906 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 55B60C88E46 for ; Thu, 10 Sep 2026 23:10:27 +0000 (UTC) Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27844.1789081821023226794 for ; Thu, 10 Sep 2026 16:10:21 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=QE6k0QdJ; spf=pass (domain: gmail.com, ip: 209.85.216.53, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-39682983a0fso329939a91.3 for ; Thu, 10 Sep 2026 16:10:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081820; x=1789686620; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=E2CZ4HPs52l9WPIkZPxtZjrAvihirNH6WSSxp7P7lOY=; b=QE6k0QdJBJmWtn7XuHjMoqB1Y4V6Med5QeFP+beajVxkLJRvEMaaSjFgRoxbDLZkyH WtrEUmWFdUwaYH4jnIyO/TQp7tvdZAVtIrrtGn6oQKA8UKFBuvRXq6egADzGVXcslDav R+fpm7TypDDUml760UavzAUZ83k9bU7bAvJinDQDDN6HyD7BqAuHE/UT4NS5fWcbi3br t/zAyHITAnzqadl709CpKvAB7xL/YtxUxA+0oaYMQ0fq7HOAe/GYEwhXM8sWYEHW4Gex kPKjYx4I4YFOLNG5xaY+BW8HrDyMxIMY88S/5k7Aqz6I9+e0PyyzhPKhtGvuLCG5+a0V utoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081820; x=1789686620; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=E2CZ4HPs52l9WPIkZPxtZjrAvihirNH6WSSxp7P7lOY=; b=Vc3bR266ewWwoFA1s8I3mPE1SbdgaaCkYWR+KSilDYG0Qq8S2FhSgrxto5fVMkxYHp qm1TJAL0iRWkkn8lj5/+rbt+NDWT/q//tiRM4YEe2dVdGkFMj7o6fjJ0eTo2NXoI/T80 hskydl8pfHdrF7YxMrIBcq/3L2Rf6RDpU2gmD7XFZMzR2iNUAwS/YuvOrVkWi10Zpj9a n6Dza+E8AhC5bYB238K3+czzEg77oI/jzTahBSWGbFEfmrgU1rG804AxzHt9gJx68ANc MyJHp6K3nJbm4+S9vJVBTvkotT7Ih/zyDDG+jC8YT6Mec61UjpsM8uG96ki0FIe4/DpN n7ZQ== X-Gm-Message-State: AFuF++kY9FI3jdHiYS/YFN4OMTuaWzJMUxTln0oX4Q8xyuPzaaosZnAN 41kNWAU1ARm529ufwPgS2d8qFfR5YiFObhLSWPkrtegFJgaLnm37GJqh7l1koA== X-Gm-Gg: AYBFou1x8Tlj/s3iGxMc3v/CkQcjDTD3ElI18uAitYZFwLiEaottV69/Pr9QuNq031c E1OQKMUbPcdS+XOkJmbwLGRgJoG01EFmgiSe7aVCmxCk23TljWc3boPGDXiHmkKwmEi12yC/JQn 3vGGtjglsLnJBNb9Mk6GYv5D2yKNLonbWRR1slIDPAYQuC5tsncnoI+BXjZWcZUmNmfuw+UIgo4 7fDrO24S889ep0nM/EAK4a4//JXhoZ/K5RmzHpB6lIxpHVBMKVLD4W0n50dK/rJAn7Fk9rRLLdF xRN/I/2SFC9qmbAaFI9Lyv4toijrT5N6j4kJ6iy/0/OJ5UMIiUe73pJUiAzSTk59QDcuZRLdqEN dlVWU+gurzhDfWoZSx6s/zivcQpbK68qNGOq6uCdBOtjE7uJSSngheWkPoAfP7B8FuIizfwz7Jh bpbWOT87Qy/uFbrEVxbnQJmp7d1uj6FZhOrc7dczWkP64KR8eDVbnEeArZWXBbJ4YK8Kp73dox6 uUfdvN9GIMEqTqdNb38aq5oBEtXWWYVPQ== X-Received: by 2002:a17:90b:51c3:b0:398:9bd5:490c with SMTP id 98e67ed59e1d1-39d9c2276fdmr1973159a91.19.1789081820377; Thu, 10 Sep 2026 16:10:20 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:19 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 13/32] unbound: patch CVE-2026-46582 Date: Fri, 11 Sep 2026 11:09:12 +1200 Message-ID: <20260910230932.173913-13-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129931 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-46582 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-46582.patch | 151 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 152 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-46582.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-46582.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-46582.patch new file mode 100644 index 0000000000..2091e1622a --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-46582.patch @@ -0,0 +1,151 @@ +From 97245ce2852162fbf19cc23b016ee73fe2aec63c Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:07:52 +0200 +Subject: [PATCH] - Fix CVE-2026-46582, A wildcard replay, as another piece of + data, triggers poisoning in the serve expired reply path. Thanks to Qifan + Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit fea0ff550bb6193417c9b17ffff409eb6736f90d) + +CVE: CVE-2026-46582 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/fea0ff550bb6193417c9b17ffff409eb6736f90d] + +Signed-off-by: Ankur Tyagi +--- + validator/val_utils.c | 15 ++++++++++++--- + validator/validator.c | 31 ++++++++++++++++++++++++++++++- + 2 files changed, 42 insertions(+), 4 deletions(-) + +diff --git a/validator/val_utils.c b/validator/val_utils.c +index 4495695ac..87c5a034a 100644 +--- a/validator/val_utils.c ++++ b/validator/val_utils.c +@@ -439,10 +439,15 @@ val_verify_rrset(struct module_env* env, struct val_env* ve, + * only improves security status + * and bogus is set only once, even if we rechecked the status */ + if(sec > d->security) { ++ int wc_expanded = 0; + d->security = sec; +- if(sec == sec_status_secure) ++ if(sec == sec_status_secure) { ++ uint8_t* wc = NULL; ++ size_t wclen = 0; + d->trust = rrset_trust_validated; +- else if(sec == sec_status_bogus) { ++ if(val_rrset_wildcard(rrset, &wc, &wclen) && wc) ++ wc_expanded = 1; ++ } else if(sec == sec_status_bogus) { + size_t i; + /* update ttl for rrset to fixed value. */ + d->ttl = ve->bogus_ttl; +@@ -455,7 +460,11 @@ val_verify_rrset(struct module_env* env, struct val_env* ve, + lock_basic_unlock(&ve->bogus_lock); + } + /* if status updated - store in cache for reuse */ +- rrset_update_sec_status(env->rrset_cache, rrset, *env->now); ++ /* For a wildcard rrset, that is secure, do not store this ++ * into the cache, because it changes proofs around the ++ * item. */ ++ if(!wc_expanded) ++ rrset_update_sec_status(env->rrset_cache, rrset, *env->now); + } + + return sec; +diff --git a/validator/validator.c b/validator/validator.c +index 5817fc808..68c4bf643 100644 +--- a/validator/validator.c ++++ b/validator/validator.c +@@ -1013,6 +1013,9 @@ validate_positive_response(struct module_env* env, struct val_env* ve, + size_t wl; + int wc_cached = 0; + int wc_NSEC_ok = 0; ++ /* This is used to update the RRset cache, with the combination ++ * of the dname expansion and this wildcard, for security status. */ ++ struct ub_packed_rrset_key* wc_rrset = NULL; + int nsec3s_seen = 0; + size_t i; + struct ub_packed_rrset_key* s; +@@ -1031,6 +1034,9 @@ validate_positive_response(struct module_env* env, struct val_env* ve, + ntohs(s->rk.type), ntohs(s->rk.rrset_class)); + chase_reply->security = sec_status_bogus; + update_reason_bogus(chase_reply, LDNS_EDE_DNSSEC_BOGUS); ++ if(wc_rrset) ++ ((struct packed_rrset_data*)wc_rrset-> ++ entry.data)->security = sec_status_bogus; + return; + } + if(wc && !wc_cached && env->cfg->aggressive_nsec) { +@@ -1038,7 +1044,7 @@ validate_positive_response(struct module_env* env, struct val_env* ve, + env->alloc, *env->now); + wc_cached = 1; + } +- ++ if(wc) wc_rrset = s; + } + + /* validate the AUTHORITY section as well - this will generally be +@@ -1095,6 +1101,9 @@ validate_positive_response(struct module_env* env, struct val_env* ve, + "did not exist"); + chase_reply->security = sec_status_bogus; + update_reason_bogus(chase_reply, LDNS_EDE_DNSSEC_BOGUS); ++ if(wc_rrset) ++ ((struct packed_rrset_data*)wc_rrset-> ++ entry.data)->security = sec_status_bogus; + return; + } + +@@ -1496,6 +1505,16 @@ validate_any_response(struct module_env* env, struct val_env* ve, + "did not exist"); + chase_reply->security = sec_status_bogus; + update_reason_bogus(chase_reply, LDNS_EDE_DNSSEC_BOGUS); ++ /* Make the expanded name and wildcard RRSIG rrsets bogus */ ++ for(i=0; ian_numrrsets; i++) { ++ uint8_t* cwc = NULL; ++ size_t cwl = 0; ++ s = chase_reply->rrsets[i]; ++ if(val_rrset_wildcard(s, &cwc, &cwl) && cwc) { ++ ((struct packed_rrset_data*)s-> ++ entry.data)->security = sec_status_bogus; ++ } ++ } + return; + } + +@@ -1533,6 +1552,9 @@ validate_cname_response(struct module_env* env, struct val_env* ve, + uint8_t* wc = NULL; + size_t wl; + int wc_NSEC_ok = 0; ++ /* This is used to update the RRset cache, with the combination ++ * of the dname expansion and this wildcard, for security status. */ ++ struct ub_packed_rrset_key* wc_rrset = NULL; + int nsec3s_seen = 0; + size_t i; + struct ub_packed_rrset_key* s; +@@ -1553,6 +1575,7 @@ validate_cname_response(struct module_env* env, struct val_env* ve, + update_reason_bogus(chase_reply, LDNS_EDE_DNSSEC_BOGUS); + return; + } ++ if(wc) wc_rrset = s; + + /* Refuse wildcarded DNAMEs rfc 4597. + * Do not follow a wildcarded DNAME because +@@ -1564,6 +1587,9 @@ validate_cname_response(struct module_env* env, struct val_env* ve, + ntohs(s->rk.type), ntohs(s->rk.rrset_class)); + chase_reply->security = sec_status_bogus; + update_reason_bogus(chase_reply, LDNS_EDE_DNSSEC_BOGUS); ++ if(wc_rrset) ++ ((struct packed_rrset_data*)wc_rrset-> ++ entry.data)->security = sec_status_bogus; + return; + } + +@@ -1628,6 +1654,9 @@ validate_cname_response(struct module_env* env, struct val_env* ve, + "did not exist"); + chase_reply->security = sec_status_bogus; + update_reason_bogus(chase_reply, LDNS_EDE_DNSSEC_BOGUS); ++ if(wc_rrset) ++ ((struct packed_rrset_data*)wc_rrset-> ++ entry.data)->security = sec_status_bogus; + return; + } + diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 8bd8732fe4..bf17c30572 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -23,6 +23,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42960.patch \ file://CVE-2026-44390.patch \ file://CVE-2026-44608.patch \ + file://CVE-2026-46582.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:13 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97905 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 6EEC8C88E48 for ; Thu, 10 Sep 2026 23:10:27 +0000 (UTC) Received: from mail-pj1-f50.google.com (mail-pj1-f50.google.com [209.85.216.50]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27846.1789081823981230322 for ; Thu, 10 Sep 2026 16:10:24 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=l6AUFG50; spf=pass (domain: gmail.com, ip: 209.85.216.50, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f50.google.com with SMTP id 98e67ed59e1d1-38ea87caafeso280529a91.3 for ; Thu, 10 Sep 2026 16:10:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081823; x=1789686623; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=i5VZoGVo7eMO+DceJpcVERYD4xg2YXNO8kTRyEVKZvk=; b=l6AUFG50nlSrqBn3XnRaotrJVSsNfGp8Ca61i0JormEkJLeB4hrPWWeUYX1uc6NSaM DHuUWlCwvIAG5x/b+Dktzwft2nmAGtkWjQPl05BxYqCAAkij9lui6PVUI6UvozS2OjMj 6unqWhdldZIJfrsBkvWMT0HdeOcLOoN6ZXJTGc63eBoK8F/OHdTww3fQg4iJz058UbR8 t5iV7JHNeOZwqIJdI/mtZprUDMczheIOECTFB6T3eVLLuY/CGDJmvUbL1OVbO7dH1Qb8 jktWPqAEO5x1VpJYx2v+AJc0LQ8wvoPQstskB6I18zfDf3l6DYE6u2tuNzb1qu4XxrU/ J4IQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081823; x=1789686623; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=i5VZoGVo7eMO+DceJpcVERYD4xg2YXNO8kTRyEVKZvk=; b=pbC5OApKwLjvmw7/YTRBnTspATXRootz0cFh9Wf/KAZeJtpSw9rDYvccUfsZgR8x60 sMDrU0gQ9rcK1E1eIIDuU3SH0ImY8mlT3drj8uqUM3NFUZIgpiY+a8qwge+X3GInoj1F X6o5IdzCpiWP6s3ThhWM/mqgLs5ECsWs0nDX/jtVDLD6Or45/69TGKwdfvTOkfVFVkiN 7ON8iCxMv10umGrF+ui8MBXtdrx21ia60CV0eStVeMc0kE4gEfuhItbokAES6UiCB+QM Zs+0aBOpXXs1NssO3pf3JNe52DkDBzVTM68bsKZpqdvNlHjNOmOlYja1GO+53bZTyQnk Cbyg== X-Gm-Message-State: AFuF++lPXXlyfp9dorcss7MW40ct1sZtGBZHzTgrrsMvWuGzXypzi2HW jjE5P2FY1n1o1jCT9uRPC3wf99Cjk+QUit1hJ7BQJN6gvISC2EGZamnGyKgOdg== X-Gm-Gg: AYBFou26BxkHStLfI7Z4Ivg9OJqUP35XZiJbE6zl02+C58jd+k1xkeX5jrthDLJBm4y gsV4LwRyBtsa0ovk/Uy2Ixc/tKbSr7ZhSbaHNkaovMR9SWI8J5rmyLivM3Wml8iG0NYIDFWRAu6 kpmo/6sNgpsb3N7dKoEtSeQJFDwGpYoUnDxAtv9s3nmWwjuu1yAhXvQHII1/QylLT3+G3y4tHyZ +yR163gx0w6M0z1m5sUs7UTLFb+pr28jLVbzNINDH8dA0/i9Hsuj8HeJVcJnrgRxcfs1sQuCrPh 5RNbzOcFVor+J1rlYdadkNvSvENayI/IsQIkWtfF68oiSnu4iL3JTcs4ZfwqFXoXNOvfWmC8Az/ deUBWKd+dCbx0Ff1mDWd0MRAeLzR0INrDkwnFj6oiv00k0srT43zs3kntdp66zXOoRtycof3sTL X85/WkKUsN6p6ye8g5y9XX211PSk0yH6fFaA40xguHRAkAE+q96bR8VzMnHgJS9wSoHt61QZgPW +NCfLDBdwFGrN5C3wQfDjs= X-Received: by 2002:a17:90b:5790:b0:398:9be9:ab8e with SMTP id 98e67ed59e1d1-39d9c21b847mr1770026a91.19.1789081823249; Thu, 10 Sep 2026 16:10:23 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:22 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 14/32] unbound: patch CVE-2026-32665 Date: Fri, 11 Sep 2026 11:09:13 +1200 Message-ID: <20260910230932.173913-14-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129932 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-32665 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-32665.patch | 119 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 120 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-32665.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-32665.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-32665.patch new file mode 100644 index 0000000000..401f8d094d --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-32665.patch @@ -0,0 +1,119 @@ +From c9bd4309ec14f767db0d0de5647f0e8fe554b60d Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:09:26 +0200 +Subject: [PATCH] - Fix CVE-2026-32665, Remote DNS-over-QUIC denial of + service due to `quic-size` budget bypass. Thanks to N0zoM1z0 + (https://github.com/N0zoM1z0) for the report. In addition, thanks to Kunta + Chu, Kaihua Wang, and Jianjun Chen from Tsinghua University, for also + reporting this issue. In addition, thanks to Qifan Zhang, Palo Alto + Networks, for also reporting this issue. In addition, thanks to Xuanchao + Xie, for also reporting this issue. + +(cherry picked from commit 01dfd2f466d383370405d8ecf939570947f3523e) + +CVE: CVE-2026-32665 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/01dfd2f466d383370405d8ecf939570947f3523e] + +Signed-off-by: Ankur Tyagi +--- + services/listen_dnsport.c | 32 ++++++++++++++++++++++---------- + 1 file changed, 22 insertions(+), 10 deletions(-) + +diff --git a/services/listen_dnsport.c b/services/listen_dnsport.c +index f7fcca194..3c5010b6b 100644 +--- a/services/listen_dnsport.c ++++ b/services/listen_dnsport.c +@@ -3978,7 +3978,8 @@ doq_stream_close(struct doq_conn* conn, struct doq_stream* stream, + + /** doq stream pick up answer data from buffer */ + static int +-doq_stream_pickup_answer(struct doq_stream* stream, struct sldns_buffer* buf) ++doq_stream_pickup_answer(struct doq_conn* conn, struct doq_stream* stream, ++ struct sldns_buffer* buf) + { + stream->is_answer_available = 1; + if(stream->out) { +@@ -3988,6 +3989,11 @@ doq_stream_pickup_answer(struct doq_stream* stream, struct sldns_buffer* buf) + } + stream->nwrite = 0; + stream->outlen = sldns_buffer_limit(buf); ++ if(!doq_table_quic_size_available(conn->doq_socket->table, ++ conn->doq_socket->cfg, stream->outlen)) { ++ verbose(VERB_ALGO, "doq stream: no space for reply length"); ++ return 0; ++ } + /* For quic the output bytes have to stay allocated and available, + * for potential resends, until the remote end has acknowledged them. + * This includes the tcplen start uint16_t, in outlen_wire. */ +@@ -4014,7 +4020,7 @@ doq_stream_send_reply(struct doq_conn* conn, struct doq_stream* stream, + if(stream->out) + doq_table_quic_size_subtract(conn->doq_socket->table, + stream->outlen); +- if(!doq_stream_pickup_answer(stream, buf)) ++ if(!doq_stream_pickup_answer(conn, stream, buf)) + return 0; + doq_table_quic_size_add(conn->doq_socket->table, stream->outlen); + doq_stream_on_write_list(conn, stream); +@@ -4025,13 +4031,19 @@ doq_stream_send_reply(struct doq_conn* conn, struct doq_stream* stream, + /** doq stream data length has completed, allocations can be done. False on + * allocation failure. */ + static int +-doq_stream_datalen_complete(struct doq_stream* stream, struct doq_table* table) ++doq_stream_datalen_complete(struct doq_conn* conn, struct doq_stream* stream, ++ struct doq_table* table) + { + if(stream->inlen > 1024*1024) { + log_err("doq stream in length too large %d", + (int)stream->inlen); + return 0; + } ++ if(!doq_table_quic_size_available(table, conn->doq_socket->cfg, ++ stream->inlen)) { ++ verbose(VERB_ALGO, "doq stream: no space for query length"); ++ return 0; ++ } + stream->in = calloc(1, stream->inlen); + if(!stream->in) { + log_err("doq could not read stream, calloc failed: " +@@ -4092,8 +4104,9 @@ doq_stream_data_complete(struct doq_conn* conn, struct doq_stream* stream) + + /** doq receive data for a stream, more bytes of the incoming data */ + static int +-doq_stream_recv_data(struct doq_stream* stream, const uint8_t* data, +- size_t datalen, int* recv_done, struct doq_table* table) ++doq_stream_recv_data(struct doq_conn* conn, struct doq_stream* stream, ++ const uint8_t* data, size_t datalen, int* recv_done, ++ struct doq_table* table) + { + int got_data = 0; + /* read the tcplength uint16_t at the start */ +@@ -4114,7 +4127,7 @@ doq_stream_recv_data(struct doq_stream* stream, const uint8_t* data, + if(stream->nread == 2) { + /* the initial length value is completed */ + stream->inlen = ntohs(tcplen); +- if(!doq_stream_datalen_complete(stream, table)) ++ if(!doq_stream_datalen_complete(conn, stream, table)) + return 0; + } else { + /* store for later */ +@@ -4331,8 +4344,7 @@ doq_stream_open_cb(ngtcp2_conn* ATTR_UNUSED(conn), int64_t stream_id, + verbose(VERB_ALGO, "doq: stream with this id already exists"); + return 0; + } +- if(stream_id != 0 && stream_id != 4 && /* allow one stream on a new connection */ +- !doq_table_quic_size_available(doq_conn->doq_socket->table, ++ if(!doq_table_quic_size_available(doq_conn->doq_socket->table, + doq_conn->doq_socket->cfg, sizeof(*stream) + + 100 /* estimated query in */ + + 512 /* estimated response out */ +@@ -4390,8 +4402,8 @@ doq_recv_stream_data_cb(ngtcp2_conn* ATTR_UNUSED(conn), uint32_t flags, + return 0; + } + if(datalen != 0) { +- if(!doq_stream_recv_data(stream, data, datalen, &recv_done, +- doq_conn->doq_socket->table)) ++ if(!doq_stream_recv_data(doq_conn, stream, data, datalen, ++ &recv_done, doq_conn->doq_socket->table)) + return NGTCP2_ERR_CALLBACK_FAILURE; + } + if((flags&NGTCP2_STREAM_DATA_FLAG_FIN)!=0) { diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index bf17c30572..12e3deb6e4 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -24,6 +24,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-44390.patch \ file://CVE-2026-44608.patch \ file://CVE-2026-46582.patch \ + file://CVE-2026-32665.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97904 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4648DC79FBB for ; Thu, 10 Sep 2026 23:10:27 +0000 (UTC) Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27847.1789081826775938233 for ; Thu, 10 Sep 2026 16:10:26 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=XjED/DIK; spf=pass (domain: gmail.com, ip: 209.85.216.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-3990fe066ebso241196a91.1 for ; Thu, 10 Sep 2026 16:10:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081826; x=1789686626; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Thz1GNaWb7wB9BBJpVaV2SCrMrZ3r1cOXSeZ8VT4TOw=; b=XjED/DIKtfVCCFS3qYNRqzSGOK6z0r/d31JW7rpgFS1HcTKLR+tTm3iMxp/p0mQvC3 gd16/fqovJtLjA8Z4mdFdZDq3emQXXcvHyjzQiCOPN5DNMHXJrQSODlHnS5i6Mcx2kx0 EBenIvwOWROJo9cjB4u9IoAfuiWYWlwK2PwYnO1Aqil+Ru99bzVGqbtOtmIf5ifijBP7 zg9mrv15o7RsddbvNE2bcoq+67uPU/KBbir3CTupHd7ep9VcAXs4dCILc6a3jGEFmhQ+ zdGj+dUve6ic8yYLxvNZUz6X+eD59HwtC3dI/sySX5+/bFzMcLul4LEz36LvLOKOsDUq oP3g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081826; x=1789686626; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Thz1GNaWb7wB9BBJpVaV2SCrMrZ3r1cOXSeZ8VT4TOw=; b=hSeDqqNfw92akOnW+W8ceUyevT2YTXbuxOkATXsVxGaE3lPJbH6Gr51S9nnva9rzKh /8Arc95G9P/33EWOPS6KHP10+2CtLhbHJtLEyqZAN+SwulVUAo/tHmr2dpZQGsBXj320 iCXV4z/eK4hFhm7T5B4zRolAn2O/0yU2dwNODMGQqrBEy3ddoS3L//BHZShRQAuFEpCF bnHqWGR4UTuiiA8QsO+axoKhTp/kvfFQ3uk9b/0IIxQWRUYjboHXo1WXm1vTaMGLNR4E OYL5eYBCS5h2JUwnLRp8oQt3oYiL0L3/bjRSXePqLGQVgHowlxPWSahVyATrm0ZHrTEj jAZA== X-Gm-Message-State: AFuF++m5WHixmdTJXf+egV9axJNCY8TxMo69+2ZyYtGO52hlXrFO0LqT Fa5soI9EI5TtODCnQ5SGvfzeCAmRDoY4Q+A6lvxroe39IsjgdSKo/+N3ocpDYQ== X-Gm-Gg: AYBFou0bT91mLiTpwoR4PEw/IARqycUpAG6g3s4RG2qUAR4sbiZRdj+vGQpEij7/O5k qO/R4RH3hniQTpXLXCGnQ7fgB9NWZmQOJ41Y5v4XHBx5ZRlUDDiCK9BTDBk9Q7dfQn+uex6A5V4 qrOwxBeqUcTDUKBBMr5xb2CpbBOb6w9QsSB5JlGIt7sBCZ1ao2hNGe/B8Zf2eJ3lW4tBcPvvBle GyuoBaVUtXCOWzPq4bhjUHSq/d8Rok+q9qpETxua+zLjwL1GJ6Sjc4ZxwPftjvF2STGwj13B8To IxFC2L8y1Tu3cCSRmYT5X4Qa8tRoaS7uwLHz0G3tzrFJaLzZmf71bMPGh5eAnycVPdgEygP3tOr 6yBF3/iwe63xg4Pd8U3Y9ic3nvkNHAVLYIC8o1FdxCPLPqdT03GRl/RFVCkp9BGP/knl0bmRpIm GKKWuQt4IKEEMZcT0eJxhVARepex+175ppyjVxGN4b2vYFzGRziLCliqyLFZpnykRt6Wmlyvp8H 1YNpa/PUj+3+WZlDcEvFuE= X-Received: by 2002:a17:90b:5605:b0:398:b17b:3bd2 with SMTP id 98e67ed59e1d1-39d9bbc9177mr1686387a91.4.1789081825988; Thu, 10 Sep 2026 16:10:25 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:25 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 15/32] unbound: patch CVE-2026-42955 Date: Fri, 11 Sep 2026 11:09:14 +1200 Message-ID: <20260910230932.173913-15-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:27 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129933 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-42955 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-42955.patch | 98 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 99 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-42955.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-42955.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42955.patch new file mode 100644 index 0000000000..aa6c7a1dd5 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-42955.patch @@ -0,0 +1,98 @@ +From 40a9f83c64c94b974e6b6f75e4ef350debf86577 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:11:04 +0200 +Subject: [PATCH] - Fix CVE-2026-42955, Extra fix for CVE-2026-40622 to also + clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' + delegation renewal via glue records. Thanks to Qifan Zhang, Palo Alto + Networks, for the report. + +(cherry picked from commit 13ec8d0f261ee7900ac67cfece551e8a703d14b1) + +CVE: CVE-2026-42955 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/13ec8d0f261ee7900ac67cfece551e8a703d14b1] + +Signed-off-by: Ankur Tyagi +--- + services/cache/rrset.c | 12 +++++++++--- + testdata/iter_prefetch_fail.rpl | 8 ++++---- + 2 files changed, 13 insertions(+), 7 deletions(-) + +diff --git a/services/cache/rrset.c b/services/cache/rrset.c +index 81f4e2820..b5fee1dc9 100644 +--- a/services/cache/rrset.c ++++ b/services/cache/rrset.c +@@ -126,7 +126,8 @@ rrset_cache_touch(struct rrset_cache* r, struct ub_packed_rrset_key* key, + + /** see if rrset needs to be updated in the cache */ + static int +-need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns) ++need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns, ++ int a_aaaa) + { + struct packed_rrset_data* newd = (struct packed_rrset_data*)nd; + struct packed_rrset_data* cached = (struct packed_rrset_data*)cd; +@@ -151,9 +152,13 @@ need_to_update_rrset(void* nd, void* cd, time_t timenow, int equal, int ns) + return 0; + /* ghost-domain: never let an NS overwrite extend lifetime + * past the entry it replaces, regardless of trust. */ +- if(ns && !TTL_IS_EXPIRED(cached->ttl, timenow) && ++ /* Also for A/AAAA and it is glue. */ ++ if((ns || ++ (a_aaaa && cached->trust==rrset_trust_add_noAA)) ++ && !TTL_IS_EXPIRED(cached->ttl, timenow) && + newd->ttl > cached->ttl) { + size_t i; ++ if(a_aaaa) newd->trust=rrset_trust_add_noAA; + newd->ttl = cached->ttl; + for(i=0; i<(newd->count+newd->rrsig_count); i++) + if(newd->rr_ttl[i] > newd->ttl) +@@ -223,7 +228,8 @@ rrset_cache_update(struct rrset_cache* r, struct rrset_ref* ref, + equal = rrsetdata_equal((struct packed_rrset_data*)k->entry. + data, (struct packed_rrset_data*)e->data); + if(!need_to_update_rrset(k->entry.data, e->data, timenow, +- equal, (rrset_type==LDNS_RR_TYPE_NS))) { ++ equal, (rrset_type==LDNS_RR_TYPE_NS), ++ (rrset_type==LDNS_RR_TYPE_A || rrset_type==LDNS_RR_TYPE_AAAA))) { + /* cache is superior, return that value */ + lock_rw_unlock(&e->lock); + ub_packed_rrset_parsedelete(k, alloc); +diff --git a/testdata/iter_prefetch_fail.rpl b/testdata/iter_prefetch_fail.rpl +index d1e308305..aa94d0fe5 100644 +--- a/testdata/iter_prefetch_fail.rpl ++++ b/testdata/iter_prefetch_fail.rpl +@@ -319,7 +319,7 @@ example.com. 360 IN NS ns.example.com. + SECTION ADDITIONAL + ; this is picked up from the parent (because this simulation has the + ; parent respond with servfail, not actually timeout) +-ns.example.com. 3600 IN A 1.2.3.4 ++ns.example.com. 360 IN A 1.2.3.4 + ENTRY_END + + ; another query to see if there is another lookup towards the authority +@@ -342,7 +342,7 @@ www.example.com. 360 IN A 10.20.30.40 + SECTION AUTHORITY + example.com. 360 IN NS ns.example.com. + SECTION ADDITIONAL +-ns.example.com. 3600 IN A 1.2.3.4 ++ns.example.com. 360 IN A 1.2.3.4 + ENTRY_END + + ; some time later another query, and now it is fine to bother the authority +@@ -367,7 +367,7 @@ www.example.com. 330 IN A 10.20.30.40 + SECTION AUTHORITY + example.com. 330 IN NS ns.example.com. + SECTION ADDITIONAL +-ns.example.com. 3570 IN A 1.2.3.4 ++ns.example.com. 330 IN A 1.2.3.4 + ENTRY_END + ; now the just-looked-up entry + STEP 190 QUERY +@@ -388,7 +388,7 @@ www.example.com. 3600 IN A 10.20.30.40 + SECTION AUTHORITY + example.com. 3600 IN NS ns.example.com. + SECTION ADDITIONAL +-ns.example.com. 3570 IN A 1.2.3.4 ++ns.example.com. 3600 IN A 1.2.3.4 + ENTRY_END + + diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 12e3deb6e4..5c798c00d3 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -25,6 +25,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-44608.patch \ file://CVE-2026-46582.patch \ file://CVE-2026-32665.patch \ + file://CVE-2026-42955.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:15 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97908 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 734D1C79FBB for ; Thu, 10 Sep 2026 23:10:37 +0000 (UTC) Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27849.1789081829294254325 for ; Thu, 10 Sep 2026 16:10:29 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=pvGE4hBa; spf=pass (domain: gmail.com, ip: 209.85.216.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-3856d6fbcb3so274441a91.2 for ; Thu, 10 Sep 2026 16:10:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081829; x=1789686629; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=SPaSuiideSO7RsoEkXuvfVLb8kbd/nD1c3cECf405dU=; b=pvGE4hBaGOAqBif6BzXpNqOpQhhyakchYiZo5chcIiD7jugGt54kwktVRVh/eIhzAD 6sHsPm+O8h9iql5TLO6UYXefO0DexZ5alJ6XSia7TP4psPXJFNa+jXcrqhCxgTIvwhYy 70uJPHg5iO1p/IaxSI/d4xuk15dyBYLkop0MXqkZY2n79ItT4O2xLd/84Vz6T+CUSfhE j2MGo7P7UmDJu+XwAfj3zKuIQHwBm50ljVJdK6l1kg9VE+LUBrmcqZP2heBysNLsF1zZ f/tcP9GgfqKmyMObdGRb1tVaKWj7a6kE9RnSY1l4nS0r8nqZjGL5Ty+SOutdSZTKxC65 iO8g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081829; x=1789686629; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=SPaSuiideSO7RsoEkXuvfVLb8kbd/nD1c3cECf405dU=; b=OQ8eQ/bSICdHqOdux2yYTKtyikO2UOWMC7CKniPHHxE9nemvxEkJEHrrDCp5C2qQE7 gDXagHF8wubeXAR0YcJCSrrOL0EFp7CKIWns0L/RTqF9wi2q7TljxZEkYQ9rGuxtACpH Kq+RQ6whBxlV9kXX2orFT+1Y7TRj3/m8ElOSSjII3/oWtTCagmAcPcZazaZllpsHfA8G 09KAEGfA3klOTCUyL8wjwDRlBOE3vsE0GQ04+sLQoGNAgjmF7MPi/86kyJsbNDlWXWDI 7kcE/HLltgcV3PDxDmwBcC8hdtbNpA3TuMg27Z8hBq0WgCW106GGOFJpdm9AcNc/6S5i WvfQ== X-Gm-Message-State: AFuF++kb7pg1nOxAhdxI2Z/0uLV6F9LHAeoY4jq/f6X4/JhT+wGfRY6x 1clK8R6kmiyPG120yqDK1h9yDRdVvE/vhFeUNrmSb5cK5AT8d43QBubXFQN4BQ== X-Gm-Gg: AYBFou2hM4Vl92UukCGCi1+Hi58LdxLN2Brrd5qx1IdhXJAYRU7rq7srYOpqZxzRu38 WM41ZBFP0nR8Gtff17Plc36yx27oamLM2K7zRDDGvJFkQxYGINI8F+ld2gHpUn/vImidogKdoue l8L+S5QkC0iUEIJcfkGaumB4gOJG26Xo6p3j7f9/0aHt4W+6JsW2Hbvcin3enOIwEtKu8ErW77h p0cbDAKBA1k9qOWd28t2ytrqPaCFskT7tHMav66KnVxFGXCb/qZ8UUciZnEcA1ojd08m9lGDLDa rDeBYSZhCOJDuWUvWDeqQ+rzcf7OSNtj70hmPFN5FvdOiyXW6BFiafBqET3hM5+z6a2WGVQk3se hFqwUly6qBykhxaNJ3+cTO/AGYlFdcDvP+m6aWGZf6txbipsKqU+Ulvd+PDlxXx8T4346XKRfoj 0Ztpa57YqRmOMzMTgk+JSrey0EWUA6yBwx7HX47yQtHuKc99QhLStmqtxRtztMvkFhn+kCxQ6iy 3k5EORTw5DZ9WsuDENspuY= X-Received: by 2002:a17:90b:4d0c:b0:395:5f43:4ec4 with SMTP id 98e67ed59e1d1-39d9b97d29emr1764829a91.0.1789081828618; Thu, 10 Sep 2026 16:10:28 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:28 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 16/32] unbound: patch CVE-2026-44621 Date: Fri, 11 Sep 2026 11:09:15 +1200 Message-ID: <20260910230932.173913-16-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129934 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-44621 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-44621.patch | 98 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 99 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-44621.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-44621.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44621.patch new file mode 100644 index 0000000000..2c581a30be --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44621.patch @@ -0,0 +1,98 @@ +From 3abdb762310bb50ef03f1ee0bbd4e09cb814fbb1 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:11:26 +0200 +Subject: [PATCH] - Fix CVE-2026-44621, Libunbound applications configured with + 'unwanted-reply-threshold' could eventually be abruptly terminated. + Thanks to Qifan Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit f52a9e864bfa0f10d8816b64130586b1d224c474) + +CVE: CVE-2026-44621 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/f52a9e864bfa0f10d8816b64130586b1d224c474] + +Signed-off-by: Ankur Tyagi +--- + daemon/worker.c | 5 +++++ + dnstap/unbound-dnstap-socket.c | 5 +++++ + smallapp/worker_cb.c | 6 ++++++ + testcode/doqclient.c | 5 +++++ + util/fptr_wlist.c | 1 + + 5 files changed, 22 insertions(+) + +diff --git a/daemon/worker.c b/daemon/worker.c +index 8e4a9b3d6..b9fac0406 100644 +--- a/daemon/worker.c ++++ b/daemon/worker.c +@@ -2560,6 +2560,11 @@ void libworker_event_done_cb(void* ATTR_UNUSED(arg), int ATTR_UNUSED(rcode), + log_assert(0); + } + ++void libworker_alloc_cleanup(void* ATTR_UNUSED(arg)) ++{ ++ log_assert(0); ++} ++ + int context_query_cmp(const void* ATTR_UNUSED(a), const void* ATTR_UNUSED(b)) + { + log_assert(0); +diff --git a/dnstap/unbound-dnstap-socket.c b/dnstap/unbound-dnstap-socket.c +index a01627de9..7d01eb220 100644 +--- a/dnstap/unbound-dnstap-socket.c ++++ b/dnstap/unbound-dnstap-socket.c +@@ -1725,6 +1725,11 @@ void libworker_event_done_cb(void* ATTR_UNUSED(arg), int ATTR_UNUSED(rcode), + log_assert(0); + } + ++void libworker_alloc_cleanup(void* ATTR_UNUSED(arg)) ++{ ++ log_assert(0); ++} ++ + int context_query_cmp(const void* ATTR_UNUSED(a), const void* ATTR_UNUSED(b)) + { + log_assert(0); +diff --git a/smallapp/worker_cb.c b/smallapp/worker_cb.c +index 92ebe386d..876c7db4e 100644 +--- a/smallapp/worker_cb.c ++++ b/smallapp/worker_cb.c +@@ -128,6 +128,12 @@ worker_alloc_cleanup(void* ATTR_UNUSED(arg)) + log_assert(0); + } + ++void ++libworker_alloc_cleanup(void* ATTR_UNUSED(arg)) ++{ ++ log_assert(0); ++} ++ + struct outbound_entry* libworker_send_query( + struct query_info* ATTR_UNUSED(qinfo), uint16_t ATTR_UNUSED(flags), + int ATTR_UNUSED(dnssec), int ATTR_UNUSED(want_dnssec), +diff --git a/testcode/doqclient.c b/testcode/doqclient.c +index 238a93803..1994cd097 100644 +--- a/testcode/doqclient.c ++++ b/testcode/doqclient.c +@@ -2671,6 +2671,11 @@ void libworker_event_done_cb(void* ATTR_UNUSED(arg), int ATTR_UNUSED(rcode), + log_assert(0); + } + ++void libworker_alloc_cleanup(void* ATTR_UNUSED(arg)) ++{ ++ log_assert(0); ++} ++ + int context_query_cmp(const void* ATTR_UNUSED(a), const void* ATTR_UNUSED(b)) + { + log_assert(0); +diff --git a/util/fptr_wlist.c b/util/fptr_wlist.c +index c6f3ca24a..3c863d5e1 100644 +--- a/util/fptr_wlist.c ++++ b/util/fptr_wlist.c +@@ -609,6 +609,7 @@ int + fptr_whitelist_alloc_cleanup(void (*fptr)(void*)) + { + if(fptr == &worker_alloc_cleanup) return 1; ++ else if(fptr == &libworker_alloc_cleanup) return 1; + return 0; + } + diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 5c798c00d3..ac8cd281d6 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -26,6 +26,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-46582.patch \ file://CVE-2026-32665.patch \ file://CVE-2026-42955.patch \ + file://CVE-2026-44621.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:16 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97907 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 7EC01C88E45 for ; Thu, 10 Sep 2026 23:10:37 +0000 (UTC) Received: from mail-pg1-f181.google.com (mail-pg1-f181.google.com [209.85.215.181]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27850.1789081831983734419 for ; Thu, 10 Sep 2026 16:10:32 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=iJBnGIKE; spf=pass (domain: gmail.com, ip: 209.85.215.181, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pg1-f181.google.com with SMTP id 41be03b00d2f7-cc1c9879395so262782a12.1 for ; Thu, 10 Sep 2026 16:10:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081831; x=1789686631; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=F7Ukf4o44XeEdRh4TL0npgmLzHgMjDi9CghX50k/zrQ=; b=iJBnGIKEZ9MNiR6xNUQtH61c3F74BVMkUAjxCb7Sp4r4vUGRKtbR2wlbWxPegsNg1K mgGLhT/MhSTuDEnP2wZHml7wYmCykhhNNCt567Xvw+K7uZCdMM8civo/4avJRad9jbcB e66Ph/pmpgpDMXUp0WhzC7DwsrGRx0Btsjm/IzLokf7czVFOa56XtPV0D/2VwHDUb7ed 73ghg3ZhNirngjl2xUORitPFh/gii5tKS8y7vqjBny84rV+M4Mi0AJ8/8hn1zFRayHjN pGVWvhZBgnlVTLx8bocEGLJmJxDFdxpLF6M7DXpe0LcYVv71WFGb4FhyXyqJKxJrm74n 4aFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081831; x=1789686631; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=F7Ukf4o44XeEdRh4TL0npgmLzHgMjDi9CghX50k/zrQ=; b=GcsLDW6NpYdK5bAft1S/5qxtFlt4NYClTecQga/hXEfz4yr7BSLqVUXj/ZnrLXoUQY prSUiP1QX9aWhs0oNf83kzrgZy6JngfKepNnopyMwVtQ4VAjQ5F/6KyV4nXmPRLkdlXS 7vGnw1rl893wX+p9LmI0Xl5Bk2LUOXwaRoTNfQRsvleh3Uf82jD+Ic4nK8sLLneMDN7I xEl2WV0mi16Eo8zY0z/qlRWCJlrQJfoJVhg8EWx2wvdUOeVOJ+z9Xraf12P5oBeer/1l W/cfRR3NjZWCHmKFL8ClkVNYtLoV8ENVwFetV9MrOKcerOAC8IGG4XQOTHhJuuhu7I6B YW7g== X-Gm-Message-State: AFuF++mBq1+N2VEo0B04SWMfxKFUsuPluKB/GtlR54D4/zgA5yXnQwq0 SkT3bT8UiuOT8Aqimc6H2hCzW9lQ0muN/Oae01m+Lh9yLfbnb7FqSgN3nN/ycQ== X-Gm-Gg: AYBFou1s+9XC+j66ygTOvA2J1imxgtDtlmeFQ8o+ENQylAXjjxliAG1AWT9oN/H4Fmq yCYLAwKpIsu5FdM07ISONoTGHZQRWYsXYT5m3aCEyxHePX8++gWooRAS03AgycFXKAHfd3fJ6O0 8tEvndkTR+zhNiDViSHpyL+mGV7yc/03cLoxqwYrmDN8YvBVogkLuXEqB1VGlQzq77UfLxNqG7N 8s8PW1FT9M5hQpE9nSa9IODrBRmjpf2LdU91UezL7b1hnvEpjWIgG3BsMvXtF86ohqZ9/Mh8tS4 oTRfmGHRKIpIQWnvReju/tme7lL+TGIr9PljHpe9/DLZQZuofVfIHorNqI8vch6ayAYz6FtgB3J h5FtXINRTALot+z9vTpvRie2ASswlqJVx1q4lRqCnHsZxy8Kchczvw0scISQO7VUUAz/JXToTdq tkDU833Yb/CsdkwueW8lphwSEjUjZuho2QU2+3uIntyHn0eQLrNsn9oJqpbTKMMUCWhH8iuH4ps tAOgBwyCZc+i2v/VcUIlVE= X-Received: by 2002:a17:90b:518f:b0:38e:97f0:aa4b with SMTP id 98e67ed59e1d1-39d9c1bef27mr1861361a91.13.1789081831215; Thu, 10 Sep 2026 16:10:31 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:30 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 17/32] unbound: patch CVE-2026-44687 Date: Fri, 11 Sep 2026 11:09:16 +1200 Message-ID: <20260910230932.173913-17-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129935 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-44687 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-44687.patch | 31 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 32 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-44687.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-44687.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44687.patch new file mode 100644 index 0000000000..03e57f6327 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-44687.patch @@ -0,0 +1,31 @@ +From ac34bce07f66a96baf85e3f25f99623b08b6dd86 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:12:03 +0200 +Subject: [PATCH] - Fix CVE-2026-44687, Off-by-one error in + 'harden-below-nxdomain' logic can shadow a stub/forward zone by a + legitimate parent's NXDOMAIN. Thanks to Qifan Zhang, Palo Alto Networks, + for the report. + +(cherry picked from commit 1e1940383ab5ee655fe7fac0da606fe59c76ce86) + +CVE: CVE-2026-44687 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/1e1940383ab5ee655fe7fac0da606fe59c76ce86] + +Signed-off-by: Ankur Tyagi +--- + services/cache/dns.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/services/cache/dns.c b/services/cache/dns.c +index 8dae2ffcc..121870ee3 100644 +--- a/services/cache/dns.c ++++ b/services/cache/dns.c +@@ -1019,7 +1019,7 @@ dns_cache_lookup(struct module_env* env, + if(env->cfg->harden_below_nxdomain) { + while(!dname_is_root(k.qname)) { + if(dpname && dpnamelen +- && !dname_subdomain_c(k.qname, dpname)) ++ && !dname_strict_subdomain_c(k.qname, dpname)) + break; /* no synth nxdomain above the stub */ + dname_remove_label(&k.qname, &k.qname_len); + h = query_info_hash(&k, flags); diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index ac8cd281d6..6cae8632ae 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -27,6 +27,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-32665.patch \ file://CVE-2026-42955.patch \ file://CVE-2026-44621.patch \ + file://CVE-2026-44687.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:17 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97909 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8CC84C88E41 for ; Thu, 10 Sep 2026 23:10:37 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27776.1789081834842101892 for ; Thu, 10 Sep 2026 16:10:34 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=J+Z753D0; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc4c3304784so348023a12.3 for ; Thu, 10 Sep 2026 16:10:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081834; x=1789686634; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MlYoj5vNmoQSYQNpQ54F3i+Us5K+qjI3WRzjVCbJUnI=; b=J+Z753D0E41zLwdhkfld4vsz6j01/P1HiyudSdAIHMGn1a/8UBlSP7Z8yIfzfVNZwz G8WTAPkIEaUg45wJDS0Iq+iK9sUxx9umEnZjC1IZeQ/J3UHzXi0cTu4rl9y4/REtBcB8 SIgIrp6v8bKnpJfcMdjMFw5BHUy0PeUT1s1BNbXHQ09TkELnM0Ac/l5LluD+cdac6RL0 UkQ+tIPBDzbO4W3mirAin12PcI7+ko3VuPMiAYO30SRtY9cVT7DfsXe7D8RTTtRjrSxp Ek1tcOd0RRpM1wvq0jEK/lQRGxosuaCqqIPg7d87dfn40mykUxZ7ML0kKRcCxlAYA6kd hQcQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081834; x=1789686634; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=MlYoj5vNmoQSYQNpQ54F3i+Us5K+qjI3WRzjVCbJUnI=; b=I+XfNxFuJIomTmSlJxgVI/ffSJ8L9cfp6kabTC++z8fElSUnnyP/GzU0x25PikyzkO KwqnnILEi/FSOvl/bJRIcLRwrHFWu9IbTrDOZjN3taU5VpR6x4kNT5TYwfReh/wtfYSA AIOOlFiqteOcZfNodOueMaN84AU7OQGhcWeus5Me2eIMYflcjvd/A8pUmz+U2N/ghuId KlR5XmqW+xrC+fr/3+TcjeipqmmQRfdrVpQy9INsuQul+VEvKkwabjyeKJZzK7j0NCWa vUX7HBZiwPB4/igBju/Iqj+g0HExUXrY+lLr+50nHqUI/KRkArpTKEROnHe3NMSxnYJQ 7LyA== X-Gm-Message-State: AFuF++lvYU1/w9nP+rIjNS5AYz/3SXO5161zk9W6SxD5iwQY2HAU/10x AUIWtmHqT4k7EGYJmSwsZZ/K+WipZ3am6B50bIk4OCyWNCsUOaOslEv6OAmIFQ== X-Gm-Gg: AYBFou3mykpeHqKk8JY3/p0zV0Ld3QAfKfIAuMEOsovwar1VFMB6TTAjw8kFmzzJECv imDdxntKEMcreTq9msxW39N8Ty+VPocGQAeQzaOUEDUrYWeeGaZJ28m0wk877a+DbQLFtRfCEUX +crFP6SFwaRR6X9+Y6JsADz5TxoiemE3SpcgIXFt9xw5WKjz4Hc5XU9AFG1y0tJ0p1L3wwoZTMh lOjju1k3wOGqJjIdIf4BNmQ4zlJRp1XU8d0/fir/yB2UllBTvvJYrmQUS3i45CkGu+0g9ITbnwH lDKUGF7do4Broweh4RSttx7hKMPSdMLTiIlRmIF7g8v8A01wstzVXT2ESXL5tiCP4sbed8lec4z 2oekaIhLgps64Ij1JCGxwOVNnT2Am6zws2GSWVZ19qKOL2u3ettsuiijyO0qvcDGCD8PcSqpJem OVECF9HRZ0z6OzqW2iQFXyI25L7gKhplfhrhe90gBVHDGLNPaDEETgHizVOrWSEZ8SbfyLsxUCo QJkGewZKUPLhVH5JgzujsE= X-Received: by 2002:a17:90b:4cce:b0:398:c9be:cca8 with SMTP id 98e67ed59e1d1-39d9bbe1915mr2029672a91.2.1789081834018; Thu, 10 Sep 2026 16:10:34 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:33 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 18/32] unbound: patch CVE-2026-50045 Date: Fri, 11 Sep 2026 11:09:17 +1200 Message-ID: <20260910230932.173913-18-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:37 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129936 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-50045 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-50045.patch | 278 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 279 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-50045.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-50045.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50045.patch new file mode 100644 index 0000000000..39c786e9a1 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50045.patch @@ -0,0 +1,278 @@ +From ceadb55a62fb7f503b13e238043a68573890db97 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:13:14 +0200 +Subject: [PATCH] - Fix CVE-2026-50045, 'max-global-quota' reset by DNSSEC + validation restarts. Thanks to Kunjie Shang, University of Science and + Technology of China, for the report. + +(cherry picked from commit 364ac737f713b2a606f0fddecddb675d72a6a991) + +CVE: CVE-2026-50045 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/364ac737f713b2a606f0fddecddb675d72a6a991] + +Signed-off-by: Ankur Tyagi +--- + iterator/iterator.c | 67 ++++++++++++++++++++++++++++++------------- + util/module.h | 6 ++++ + validator/validator.c | 13 +++++++++ + 3 files changed, 66 insertions(+), 20 deletions(-) + +diff --git a/iterator/iterator.c b/iterator/iterator.c +index 71e64655f..16dbc19de 100644 +--- a/iterator/iterator.c ++++ b/iterator/iterator.c +@@ -81,7 +81,8 @@ int BLACKLIST_PENALTY = (120000*4); + /** Timeout when only a single probe query per IP is allowed. */ + int PROBE_MAXRTO = PROBE_MAXRTO_DEFAULT; /* in msec */ + +-static void target_count_increase_nx(struct iter_qstate* iq, int num); ++static void target_count_increase_nx(struct module_qstate* qstate, ++ struct iter_qstate* iq, int num); + + int + iter_init(struct module_env* env, int id) +@@ -250,7 +251,7 @@ error_supers(struct module_qstate* qstate, int id, struct module_qstate* super) + if((dpns->got4 == 2 || (!ie->supports_ipv4 && !ie->nat64.use_nat64)) && + (dpns->got6 == 2 || !ie->supports_ipv6)) { + dpns->resolved = 1; /* mark as failed */ +- target_count_increase_nx(super_iq, 1); ++ target_count_increase_nx(super, super_iq, 1); + } + } + if(qstate->qinfo.qtype == LDNS_RR_TYPE_NS) { +@@ -733,7 +734,7 @@ is_caps_whitelisted(struct iter_env* ie, struct iter_qstate* iq) + * created for the parent query. + */ + static void +-target_count_create(struct iter_qstate* iq) ++target_count_create(struct module_qstate* qstate, struct iter_qstate* iq) + { + if(!iq->target_count) { + iq->target_count = (int*)calloc(TARGET_COUNT_MAX, sizeof(int)); +@@ -741,33 +742,57 @@ target_count_create(struct iter_qstate* iq) + if(iq->target_count) { + iq->target_count[TARGET_COUNT_REF] = 1; + iq->nxns_dp = (uint8_t**)calloc(1, sizeof(uint8_t*)); ++ /* continue global quota from where it was. */ ++ if(qstate->global_quota_reached > ++ iq->target_count[TARGET_COUNT_GLOBAL_QUOTA]) ++ iq->target_count[TARGET_COUNT_GLOBAL_QUOTA] = ++ qstate->global_quota_reached; + } + } + } + + static void +-target_count_increase(struct iter_qstate* iq, int num) ++target_count_store(struct module_qstate* qstate, struct iter_qstate* iq) + { +- target_count_create(iq); ++ if(iq->target_count) { ++ /* By storing the global quota counter, it stays ++ * there to be picked up if the module is restarted, ++ * eg. due to a validator retry, and then the ++ * target_count_create routine picks it up. */ ++ if(iq->target_count[TARGET_COUNT_GLOBAL_QUOTA] > ++ qstate->global_quota_reached) ++ qstate->global_quota_reached = ++ iq->target_count[TARGET_COUNT_GLOBAL_QUOTA]; ++ } ++} ++ ++static void ++target_count_increase(struct module_qstate* qstate, ++ struct iter_qstate* iq, int num) ++{ ++ target_count_create(qstate, iq); + if(iq->target_count) + iq->target_count[TARGET_COUNT_QUERIES] += num; + iq->dp_target_count++; + } + + static void +-target_count_increase_nx(struct iter_qstate* iq, int num) ++target_count_increase_nx(struct module_qstate* qstate, ++ struct iter_qstate* iq, int num) + { +- target_count_create(iq); ++ target_count_create(qstate, iq); + if(iq->target_count) + iq->target_count[TARGET_COUNT_NX] += num; + } + + static void +-target_count_increase_global_quota(struct iter_qstate* iq, int num) ++target_count_increase_global_quota(struct module_qstate* qstate, ++ struct iter_qstate* iq, int num) + { +- target_count_create(iq); ++ target_count_create(qstate, iq); + if(iq->target_count) + iq->target_count[TARGET_COUNT_GLOBAL_QUOTA] += num; ++ target_count_store(qstate, iq); + } + + /** +@@ -860,7 +885,7 @@ generate_sub_request(uint8_t* qname, size_t qnamelen, uint16_t qtype, + subiq = (struct iter_qstate*)subq->minfo[id]; + memset(subiq, 0, sizeof(*subiq)); + subiq->num_target_queries = 0; +- target_count_create(iq); ++ target_count_create(qstate, iq); + subiq->target_count = iq->target_count; + if(iq->target_count) { + iq->target_count[TARGET_COUNT_REF] ++; /* extra reference */ +@@ -2233,7 +2258,7 @@ processLastResort(struct module_qstate* qstate, struct iter_qstate* iq, + return error_response_cache(qstate, id, LDNS_RCODE_SERVFAIL); + } + iq->num_target_queries += qs; +- target_count_increase(iq, qs); ++ target_count_increase(qstate, iq, qs); + if(qs != 0) { + qstate->ext_state[id] = module_wait_subquery; + return 0; /* and wait for them */ +@@ -2289,7 +2314,7 @@ processLastResort(struct module_qstate* qstate, struct iter_qstate* iq, + * lookups at a time. */ + verbose(VERB_ALGO, "try parent-side glue lookup"); + iq->num_target_queries += query_count; +- target_count_increase(iq, query_count); ++ target_count_increase(qstate, iq, query_count); + qstate->ext_state[id] = module_wait_subquery; + return 0; + } +@@ -2309,7 +2334,7 @@ processLastResort(struct module_qstate* qstate, struct iter_qstate* iq, + if(query_count != 0) { /* suspend to await results */ + verbose(VERB_ALGO, "try parent-side glue lookup"); + iq->num_target_queries += query_count; +- target_count_increase(iq, query_count); ++ target_count_increase(qstate, iq, query_count); + qstate->ext_state[id] = module_wait_subquery; + return 0; + } +@@ -2789,7 +2814,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq, + return error_response_cache(qstate, id, LDNS_RCODE_SERVFAIL); + } + iq->num_target_queries += extra; +- target_count_increase(iq, extra); ++ target_count_increase(qstate, iq, extra); + if(iq->num_target_queries > 0) { + /* wait to get all targets, we want to try em */ + verbose(VERB_ALGO, "wait for all targets for fallback"); +@@ -2840,7 +2865,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq, + /* errors ignored, these targets are not strictly necessary for + * this result, we do not have to reply with SERVFAIL */ + iq->num_target_queries += extra; +- target_count_increase(iq, extra); ++ target_count_increase(qstate, iq, extra); + } + + /* Add the current set of unused targets to our queue. */ +@@ -2963,7 +2988,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq, + LDNS_RCODE_SERVFAIL); + } + iq->num_target_queries += qs; +- target_count_increase(iq, qs); ++ target_count_increase(qstate, iq, qs); + } + /* Since a target query might have been made, we + * need to check again. */ +@@ -3023,7 +3048,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq, + * this result, we do not have to reply with SERVFAIL */ + if(extra > 0) { + iq->num_target_queries += extra; +- target_count_increase(iq, extra); ++ target_count_increase(qstate, iq, extra); + check_waiting_queries(iq, qstate, id); + /* undo qname minimise step because we'll get back here + * to do it again */ +@@ -3036,7 +3061,7 @@ processQueryTargets(struct module_qstate* qstate, struct iter_qstate* iq, + } + } + +- target_count_increase_global_quota(iq, 1); ++ target_count_increase_global_quota(qstate, iq, 1); + if(iq->target_count && iq->target_count[TARGET_COUNT_GLOBAL_QUOTA] + > MAX_GLOBAL_QUOTA) { + char s[LDNS_MAX_DOMAINLEN]; +@@ -3880,7 +3905,7 @@ processTargetResponse(struct module_qstate* qstate, int id, + /* no new addresses, increase the nxns counter, like + * this could be a list of wildcards with no new + * addresses */ +- target_count_increase_nx(foriq, 1); ++ target_count_increase_nx(qstate, foriq, 1); + } + verbose(VERB_ALGO, "added target response"); + delegpt_log(VERB_ALGO, foriq->dp); +@@ -3892,7 +3917,7 @@ processTargetResponse(struct module_qstate* qstate, int id, + dpns->resolved = 1; /* fail the target */ + /* do not count cached answers */ + if(qstate->reply_origin && qstate->reply_origin->len != 0) { +- target_count_increase_nx(foriq, 1); ++ target_count_increase_nx(qstate, foriq, 1); + } + } + } +@@ -4117,6 +4142,7 @@ processFinished(struct module_qstate* qstate, struct iter_qstate* iq, + iter_store_parentside_neg(qstate->env, &qstate->qinfo, + iq->deleg_msg?iq->deleg_msg->rep: + (iq->response?iq->response->rep:NULL)); ++ target_count_store(qstate, iq); + if(!iq->response) { + verbose(VERB_ALGO, "No response is set, servfail"); + errinf(qstate, "(no response found at query finish)"); +@@ -4532,6 +4558,7 @@ iter_clear(struct module_qstate* qstate, int id) + iq = (struct iter_qstate*)qstate->minfo[id]; + if(iq) { + outbound_list_clear(&iq->outlist); ++ target_count_store(qstate, iq); + if(iq->target_count && --iq->target_count[TARGET_COUNT_REF] == 0) { + free(iq->target_count); + if(*iq->nxns_dp) free(*iq->nxns_dp); +diff --git a/util/module.h b/util/module.h +index edce4a523..b13b8de2f 100644 +--- a/util/module.h ++++ b/util/module.h +@@ -712,6 +712,12 @@ struct module_qstate { + + /** whether the reply should be dropped */ + int is_drop; ++ /** the global quota that was reached, by one of the modules. ++ * So that continued counting can go on from that point. */ ++ int global_quota_reached; ++ /** the global quota that a query started with, it is a subquery, ++ * so that calling mesh states can see the increase. */ ++ int global_quota_started; + }; + + /** +diff --git a/validator/validator.c b/validator/validator.c +index 68c4bf643..c9896e4fb 100644 +--- a/validator/validator.c ++++ b/validator/validator.c +@@ -517,6 +517,14 @@ generate_request(struct module_qstate* qstate, int id, uint8_t* name, + /* add our blacklist to the query blacklist */ + sock_list_merge(&(*newq)->blacklist, (*newq)->region, + vq->chain_blacklist); ++ /* start its global quota counter where this one is. */ ++ if(qstate->global_quota_reached > ++ (*newq)->global_quota_reached) { ++ (*newq)->global_quota_started = ++ qstate->global_quota_reached; ++ (*newq)->global_quota_reached = ++ qstate->global_quota_reached; ++ } + } + qstate->ext_state[id] = module_wait_subquery; + return 1; +@@ -3476,6 +3484,11 @@ val_inform_super(struct module_qstate* qstate, int id, + verbose(VERB_ALGO, "super: has no validator state"); + return; + } ++ /* Pick up the global quota limit from the subquery. */ ++ if(qstate->global_quota_reached > qstate->global_quota_started) { ++ super->global_quota_reached += qstate->global_quota_reached - ++ qstate->global_quota_started; ++ } + if(vq->wait_prime_ta) { + vq->wait_prime_ta = 0; + process_prime_response(super, vq, id, qstate->return_rcode, diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 6cae8632ae..28214dea19 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -28,6 +28,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-42955.patch \ file://CVE-2026-44621.patch \ file://CVE-2026-44687.patch \ + file://CVE-2026-50045.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:18 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97910 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8A20BC88E45 for ; Thu, 10 Sep 2026 23:10:47 +0000 (UTC) Received: from mail-pj1-f54.google.com (mail-pj1-f54.google.com [209.85.216.54]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27851.1789081837413270256 for ; Thu, 10 Sep 2026 16:10:37 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=W8V2y7Me; spf=pass (domain: gmail.com, ip: 209.85.216.54, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f54.google.com with SMTP id 98e67ed59e1d1-398c1101c1bso301795a91.1 for ; Thu, 10 Sep 2026 16:10:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081837; x=1789686637; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=U7WmbOCKVdldAZRrCiN+PLYSzHH00mVBVIMwOcyQH1w=; b=W8V2y7MeBhFEX56MbTuYP2pG03f+o1JWSrNHnTLYPaXZl+dEsiiRq94DqvAjNXzIv0 R1dZBESEWrOwGNuGOocRsNU/V60sXh51w6FIgV9j/XoCB8RzFUuu4QOKwPIS23WvQOYx sY5rTI+AKaBwitw0W7aSPMDkkAnaaX3TBKbZYwjWufksj8nZLkljc9bgqG+8YGfEmZGv XD6dL03ul6y7uwaLbOmXxkJrCpklHmkApYybjRJguMzEt/U9LbzEWnd2TZKqDCYRiyXz qKhM15f/cf9cA9j+aHaAfbXOwQYgMiYzbUs6Kd/33Hhze2S35e/Q/Yfr0/J8ZO9x8EwG OynA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081837; x=1789686637; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=U7WmbOCKVdldAZRrCiN+PLYSzHH00mVBVIMwOcyQH1w=; b=eejSdCM7Mylg/ImHTtyHKTIkgkasfGL+DUgpOAsoSxQrvxt449pLJWotVAyVN31oz/ 9pWYX4KMD3B9vT6cSaeNyea1Za2sC+JLhb0YwyfLqVJZgDyfR3tpA+mTsd0E/4zGeGi6 CC927cuoTkg6VcBaCdhSyRp4LIP8BjPHsV091vPkcz99c3gAGWGukHbQKP3oE3gnsi1J EwehY7OIEo60aaNzGifJnD/gVnHCkThqYEk5HPyanNbQsoPAy/fcuKgtd+Y4hqW16AMi 8nQX36uxFvsrgWgOCOj0WhPVyw4Z3s+okqmspLf7fPGbirS68uSe4EnyIV3OpOmitLtx jEyg== X-Gm-Message-State: AFuF++lEDWlQnHFnjGNMrBgqfWVH5Y+vbaOQGLxc85iFTje+YeR+2sAf J66FAvFa0CbR1vg+MIpdZVqq13nY9EEMkFKwUWK76XWF4lOTFWMCNLNe16ZxPA== X-Gm-Gg: AYBFou2MmcQzywi0vyMTnQNHfjk5aP9wG/WegtJlqnIzaUTAgXo1ixIfFmTGqfbZqgw 46Dz2CpfCHIziPdw1BQs3rApkvhxsZMAME4M+ngTfhbklIJZYI17FSQkQyC+eXgWJMH5Xw8ug39 M44gLCYLv6DV7PVKjfoAiQ8psp2FseCInfnJjVUuHl9DDulJxUEgXvW6UxMSIOLwZDjiKDKu1SG UN9+uMYkO5cLuV9wwtyCpZIhKlZsAH0CR7RwLU9W8X3ZpL3vrV0+W+98VTrCK9RGFNOLRpXUbT8 YYmqFn+NwyPBA625K6HTm7fCa5t46S8VgjYZ3PQtXGW5JjAykGkOfNpxBfRl9MnSTiVUwXjsRGb lvnY3TPr9Ef2Pw9CLZiRdRIqp0fxQG/Ja6gFZC9L0cTuzmeBO4cRfl2IG+BM/1Ggf0Ze7nRGxVw laYW/0GIAemSCxqURXEn5rv8DPPGDOevA8+ADAT1QEaeerJe4M5i90xU4in8Jbk8WL8EqKPQ0k9 HxnSit4u5OuQOkWOFFgbaBwyw== X-Received: by 2002:a17:90b:4a8c:b0:398:9c0c:7c72 with SMTP id 98e67ed59e1d1-39d9c3891d8mr1670997a91.25.1789081836701; Thu, 10 Sep 2026 16:10:36 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:36 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 19/32] unbound: patch CVE-2026-50046 Date: Fri, 11 Sep 2026 11:09:18 +1200 Message-ID: <20260910230932.173913-19-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129937 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-50046 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-50046.patch | 61 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 62 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-50046.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-50046.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50046.patch new file mode 100644 index 0000000000..018a61cf54 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50046.patch @@ -0,0 +1,61 @@ +From 513f5e4be89d3b139605dfc31c3fb3728f25be2a Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:13:36 +0200 +Subject: [PATCH] - Fix CVE-2026-50046, Possible heap use-after-free in an + error path when a DoT forwarded query is jostled out. Thanks to Qifan + Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit 1ad8d4c39594dcb28d636fb4922737a3640c9a65) + +CVE: CVE-2026-50046 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/1ad8d4c39594dcb28d636fb4922737a3640c9a65] + +Signed-off-by: Ankur Tyagi +--- + services/outside_network.c | 12 +++++++++++- + services/outside_network.h | 2 +- + 2 files changed, 12 insertions(+), 2 deletions(-) + +diff --git a/services/outside_network.c b/services/outside_network.c +index 2b7f7d0a2..bc65d36f7 100644 +--- a/services/outside_network.c ++++ b/services/outside_network.c +@@ -195,6 +195,7 @@ static void + waiting_tcp_delete(struct waiting_tcp* w) + { + if(!w) return; ++ free(w->tls_auth_name); + if(w->timer) + comm_timer_delete(w->timer); + free(w); +@@ -2489,7 +2490,16 @@ pending_tcp_query(struct serviced_query* sq, sldns_buffer* packet, + w->cb = callback; + w->cb_arg = callback_arg; + w->ssl_upstream = sq->ssl_upstream; +- w->tls_auth_name = sq->tls_auth_name; ++ if(sq->tls_auth_name) { ++ w->tls_auth_name = strdup(sq->tls_auth_name); ++ if(!w->tls_auth_name) { ++ comm_timer_delete(w->timer); ++ free(w); ++ return NULL; ++ } ++ } else { ++ w->tls_auth_name = NULL; ++ } + w->timeout = timeout; + w->id_node.key = NULL; + w->write_wait_prev = NULL; +diff --git a/services/outside_network.h b/services/outside_network.h +index 0a77e3388..81ebfe3e2 100644 +--- a/services/outside_network.h ++++ b/services/outside_network.h +@@ -412,7 +412,7 @@ struct waiting_tcp { + void* cb_arg; + /** if it uses ssl upstream */ + int ssl_upstream; +- /** ref to the tls_auth_name from the serviced_query */ ++ /** owned copy of the tls_auth_name (malloced) */ + char* tls_auth_name; + /** the packet was involved in an error, to stop looping errors */ + int error_count; diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 28214dea19..cc380f6ae0 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -29,6 +29,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-44621.patch \ file://CVE-2026-44687.patch \ file://CVE-2026-50045.patch \ + file://CVE-2026-50046.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:19 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97913 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id A020DC79FBB for ; Thu, 10 Sep 2026 23:10:47 +0000 (UTC) Received: from mail-pz2-f12.google.com (mail-pz2-f12.google.com [74.125.228.12]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27778.1789081839973929897 for ; Thu, 10 Sep 2026 16:10:40 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=VAZ5ddef; spf=pass (domain: gmail.com, ip: 74.125.228.12, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pz2-f12.google.com with SMTP id 41be03b00d2f7-cc1cea4ae2cso335974a12.0 for ; Thu, 10 Sep 2026 16:10:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081839; x=1789686639; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=My+h0OS3Mr8B4Qo+PFgGDGPcVMEjtm5eelI2KF4NzH0=; b=VAZ5ddefk2tDzHU8x7/zMKuNCXLweT3cSogRR3LY9aHu3yrhWfj+sTGAr7BXcbfCGw WvBCrFQYTPfkAZjrXMe53FJBNPZCZCJZ9iFanOT4CLiFuWAnB8y3P+JtNkpoTaUdFXOC k48UIslVTU31Y8DIlacd736SARjFe6OyA3qdvlDaf4CqLZaB42LFzRWMpd93Hm2h84J6 ZbICQR2UDW92dbxluWeILvMimewvGL9597m6WFNGvAPmoXD5qOXrEJTv/tcbs4zDKN6q j2L1b8nk7VHDN9n/KvSIvkt+Mbv4mxni+5uXuArUS/ZJOfC9ZA0BXP6NFyr/N4dA7LJr W+1A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081839; x=1789686639; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=My+h0OS3Mr8B4Qo+PFgGDGPcVMEjtm5eelI2KF4NzH0=; b=p9sHvoYvXQoPaS3bp4j/jlT0AN+P913nE+HF5sH3szBdo0bfz1C4y9/5bM7sl0BqWy 5lalkQFJuf6IgTxPXbimDkdO2WWEyUL70arki9KeKX+5Gr6xzLtDVbXqVDFsIf4dJN5O 75Q/nnrs2BOTp0BIG3X6mEZ3IHhe02698m0pEJn/p3Gv/zIgHOM3L9WsrVMJXWFG6V17 W4QkNr47pQUK6XE/ZcxNV/djC7wHJxA45AM4sY2khVwh5WywOP1JJMIRnpPyEmifht42 xUR53180J4mBTzUIo1Rpv9SPNcpOjRDBQj8AV5Oce0MbK1fZWTBrhQAJZCsHStLZMUXV i2jA== X-Gm-Message-State: AFuF++lgK/ZatRMBRo/p6XoFtrauRaqEY0IJvphEE9DH2C3y4copiV5h 5WqL+f69tLElD+fvqCLXpOHMZhXrb5TB5Ef5xOzCSikCNs1ZLgL8RMqwnWShpg== X-Gm-Gg: AYBFou1dW6FF7OL48KOMCMg8MYTnJ3n2wgaAg0AzNnF0GrgLKbyMLeEveqRJ+rf1Nbn Oxr48TsJJJrk+bTD+LEhWqYvEisaF1zwCZS+5Xdt0wjoRgGha36ES2tXfWbP2yT6WeROuKc6FDl PhOTH4UR+LZ7rgS2YkVYRK34izgYpslq+n6NCvd5NmVY+0ube640Hk1ROmyXaNXC45ILkbzQ9EJ vht7oLLyXT3yqqhuyh9YfAYnNAM1g5TKcvvy7sknYlky6cfEO5S0LOTZuIci+d6eDhuCLGVhvmz uJSi3XQL5OJ7Ts0BpEkgF4IQEUk5pCEQhRnuJyhojNB8dWvSHlMyjDR2xr48EED3LKzKN79ZQ8E /zLKfr4OHaYpLY3TEaNXKtTNaVYrEejQOpHIOoOjlzYpmGEE/tEAcSISlMnlycMbttvW4cdPntw +HBVEDYqho3CROjhjLSBSitg8pmlfnP96kECx7KmPaAqOSiwCUYt2TYKDMljttTNPuE4zFlqW8+ eR3s21v59fVLgZp431qyWQ= X-Received: by 2002:a17:90b:588d:b0:398:bacb:1137 with SMTP id 98e67ed59e1d1-39d9c3771a8mr1662211a91.19.1789081839313; Thu, 10 Sep 2026 16:10:39 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:38 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 20/32] unbound: patch CVE-2026-50243 Date: Fri, 11 Sep 2026 11:09:19 +1200 Message-ID: <20260910230932.173913-20-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129938 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-50243 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-50243.patch | 36 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 37 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-50243.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-50243.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50243.patch new file mode 100644 index 0000000000..761bc9687a --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50243.patch @@ -0,0 +1,36 @@ +From 793f66cb3c63357bd610690151a4859b159f7f5e Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:14:04 +0200 +Subject: [PATCH] - Fix CVE-2026-50243, 'response-ip'/'rpz' can rewrite BOGUS + answers instead of returning SERVFAIL. Thanks to Qifan Zhang, Palo Alto + Networks, for the report. + +(cherry picked from commit 02b16de1ae40e43a3e3804e98ab9868da33d72eb) + +CVE: CVE-2026-50243 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/02b16de1ae40e43a3e3804e98ab9868da33d72eb] + +Signed-off-by: Ankur Tyagi +--- + respip/respip.c | 8 +++++++- + 1 file changed, 7 insertions(+), 1 deletion(-) + +diff --git a/respip/respip.c b/respip/respip.c +index 353a0fd78..346f84feb 100644 +--- a/respip/respip.c ++++ b/respip/respip.c +@@ -1110,7 +1110,13 @@ respip_operate(struct module_qstate* qstate, enum module_ev event, int id, + if((qstate->qinfo.qtype == LDNS_RR_TYPE_A || + qstate->qinfo.qtype == LDNS_RR_TYPE_AAAA || + qstate->qinfo.qtype == LDNS_RR_TYPE_ANY) && +- qstate->return_msg && qstate->return_msg->rep) { ++ qstate->return_msg && qstate->return_msg->rep && ++ !(qstate->env->need_to_validate && ++ (!(qstate->query_flags & BIT_CD) ++ || qstate->env->cfg->ignore_cd) && ++ (qstate->return_msg->rep->security <= sec_status_bogus ++ || qstate->return_msg->rep->security == ++ sec_status_secure_sentinel_fail))) { + struct reply_info* new_rep = qstate->return_msg->rep; + struct ub_packed_rrset_key* alias_rrset = NULL; + struct respip_action_info actinfo = {0, 0, 0, 0, NULL, 0, NULL}; diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index cc380f6ae0..68d81fc551 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -30,6 +30,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-44687.patch \ file://CVE-2026-50045.patch \ file://CVE-2026-50046.patch \ + file://CVE-2026-50243.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:20 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97912 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id AD561C88E46 for ; Thu, 10 Sep 2026 23:10:47 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27853.1789081842624382022 for ; Thu, 10 Sep 2026 16:10:42 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=NAkYBGjt; spf=pass (domain: gmail.com, ip: 74.125.227.140, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj2-f12.google.com with SMTP id d9443c01a7336-2d90ba1d807so2690545ad.3 for ; Thu, 10 Sep 2026 16:10:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081842; x=1789686642; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=LZTxIUCN+lhsQOWyWTwMQnrMZicP2JWIdDFg/HeoRiE=; b=NAkYBGjt6z+fsttRS0adBcNyTuQX6EYWDO245Fq3MXTpNz9tE+SMsnw2sdxeDgT/BR I5Lf1dtvdaEImaNjqVnAIq3xI6pZPa0l6L8EH9bpH8WrXUzS5a6Vhn9uLr/jofW7M2gu joGXBc/3XPd1iRLUGH8jtcyKjWrg6jFsK1MofYVN16YXCq72ujhYEbrjBeVbDYwKQdiO 9Zs7ZWVc0v22MPmmhirn+j96zaQMS/MQuglePFBan3pXRJgZCHxAxjlDcjglR7NoqBKM 0IY+70QXxNcFyMV2xVeiSdwvcUVy5ItM2j6s3Ea3cWKsFesYjKHuPa2NQKmmiMZPyFvy 3aDQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081842; x=1789686642; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=LZTxIUCN+lhsQOWyWTwMQnrMZicP2JWIdDFg/HeoRiE=; b=qgBbisz7uP0Opca4WIM02Xeldpa0daKRGK7McxIIFLbxNV9jsg2xyQe26+D31LdDpn nB9UfjLEr9Qp0zbtnkYrP0nKeSs9Dh4QsAVhsCb6thsf8eTdOVJc0GVYs2R+1gWCDa9B 8meJg0U0cNA1EHby0cafjs6O2/vMtCvsf4hhzWvLM7XGFnNcshqiI6Y5t2DaNWj92nGJ y9q5qK8EH8lQcjvT5OP9Go8jRlVZIkbqCQp0M69b0xt4mYb6dU3kdA8G/VnndqX+3pih 6Djor33tzTcVokwTfdKnX0V7gmh+MZQYuu67LWVPWRHevwKShtkyyWfWHguDUHROsDcf bacg== X-Gm-Message-State: AFuF++n3JMZwXVg/pkUvCkx5gFqhI3jH/oMd7WIt5UKICMmr6hNIMDuC n8GyvSVGhYe4nKu7Mm4NAFerFdVyBvl4Un4QJP0Jzt5hqiUWCIx7T+Se2+M4Yw== X-Gm-Gg: AYBFou2lJo1quo2PzhIfEYUwvKs7Hem7se3j+mjD6WV0k+/1+6KgW+jhMJq2lc6164J NjXGn1rPY/KF7OsglosBy/uWDA+9HuSWPvhXgR9arzT+wCV4F1l1JNI6+W5FI1J7gcSEH8EJ/J6 NAAlJ6JxCKrGeb0YMa6KUBfhbLRjvifiDC6dlBW0i/CBUxe8z0Uknd6K95De8vRlBALWQjwgp8h nrw9APBM0RRqq/xCQgeWTmXguLhRR1LY/rNKhUoZdp2eBWjWcKATZTkNKsMC58jaHCP6HpJiH3t g1YucX5bat/T6EEF1Dxu5qA7l/aU6ZfhNdq7Hpjl4rXRQ6sQAYXBoVr53nq4SbIv5dXR/s5O6CQ KotIJX9iXtwxYZyi3Km67YxG+w1RWctqCf5gp/euYZpufniF7e3aPxyeIo99aSbxvFH8VWKtIMH tyq/SkBhjbfwUFz9tUCdkO4nQVO/8Y05cEtSZnptV0+6mv13iABJZYRpffBYtFJwJKuHU6B2+km m4Cq1tcdusKuT/ly6vCoR8= X-Received: by 2002:a17:90b:274b:b0:381:a766:efcb with SMTP id 98e67ed59e1d1-39d9bc6767cmr1770621a91.4.1789081841964; Thu, 10 Sep 2026 16:10:41 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:41 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 21/32] unbound: patch CVE-2026-50248 Date: Fri, 11 Sep 2026 11:09:20 +1200 Message-ID: <20260910230932.173913-21-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129939 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-50248 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-50248.patch | 77 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 78 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-50248.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-50248.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50248.patch new file mode 100644 index 0000000000..04a63d4f48 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50248.patch @@ -0,0 +1,77 @@ +From ad27c1762cd00df8b808925ab240fc4c0766c228 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:14:35 +0200 +Subject: [PATCH] - Fix CVE-2026-50248, BOGUS configured primary hostname + accepted for XFR in auth/rpz zones. Thanks to Qifan Zhang, Palo Alto + Networks, for the report. + +(cherry picked from commit 3530c81e29e64ed19c612ae3dea21c8800d882e1) + +CVE: CVE-2026-50248 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/3530c81e29e64ed19c612ae3dea21c8800d882e1] + +Signed-off-by: Ankur Tyagi +--- + services/authzone.c | 28 ++++++++++++++++++++++------ + 1 file changed, 22 insertions(+), 6 deletions(-) + +diff --git a/services/authzone.c b/services/authzone.c +index 60ccc8698..357c1c590 100644 +--- a/services/authzone.c ++++ b/services/authzone.c +@@ -5693,8 +5693,7 @@ xfr_master_add_addrs(struct auth_master* m, struct ub_packed_rrset_key* rrset, + + /** callback for task_transfer lookup of host name, of A or AAAA */ + void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf, +- enum sec_status ATTR_UNUSED(sec), char* ATTR_UNUSED(why_bogus), +- int ATTR_UNUSED(was_ratelimited)) ++ enum sec_status sec, char* why_bogus, int ATTR_UNUSED(was_ratelimited)) + { + struct auth_xfer* xfr = (struct auth_xfer*)arg; + struct module_env* env; +@@ -5707,7 +5706,16 @@ void auth_xfer_transfer_lookup_callback(void* arg, int rcode, sldns_buffer* buf, + } + + /* process result */ +- if(rcode == LDNS_RCODE_NOERROR) { ++ if(sec == sec_status_bogus || sec == sec_status_secure_sentinel_fail) { ++ if(verbosity >= VERB_OPS) { ++ char zname[LDNS_MAX_DOMAINLEN]; ++ dname_str(xfr->name, zname); ++ verbose(VERB_OPS, "auth zone %s: primary %s address lookup is DNSSEC bogus: %s", ++ zname, xfr->task_transfer->lookup_target->host, ++ (why_bogus?why_bogus:"")); ++ } ++ /* fall through to next-lookup / next-master */ ++ } else if(rcode == LDNS_RCODE_NOERROR) { + uint16_t wanted_qtype = LDNS_RR_TYPE_A; + struct regional* temp = env->scratch; + struct query_info rq; +@@ -6756,8 +6764,7 @@ xfr_probe_send_or_end(struct auth_xfer* xfr, struct module_env* env) + + /** callback for task_probe lookup of host name, of A or AAAA */ + void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf, +- enum sec_status ATTR_UNUSED(sec), char* ATTR_UNUSED(why_bogus), +- int ATTR_UNUSED(was_ratelimited)) ++ enum sec_status sec, char* why_bogus, int ATTR_UNUSED(was_ratelimited)) + { + struct auth_xfer* xfr = (struct auth_xfer*)arg; + struct module_env* env; +@@ -6770,7 +6777,16 @@ void auth_xfer_probe_lookup_callback(void* arg, int rcode, sldns_buffer* buf, + } + + /* process result */ +- if(rcode == LDNS_RCODE_NOERROR) { ++ if(sec == sec_status_bogus || sec == sec_status_secure_sentinel_fail) { ++ if(verbosity >= VERB_OPS) { ++ char zname[LDNS_MAX_DOMAINLEN]; ++ dname_str(xfr->name, zname); ++ verbose(VERB_OPS, "auth zone %s: primary %s address probe lookup is DNSSEC bogus: %s", ++ zname, xfr->task_transfer->lookup_target->host, ++ (why_bogus?why_bogus:"")); ++ } ++ /* fall through to next-lookup / next-master */ ++ } else if(rcode == LDNS_RCODE_NOERROR) { + uint16_t wanted_qtype = LDNS_RR_TYPE_A; + struct regional* temp = env->scratch; + struct query_info rq; diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 68d81fc551..b6b6ecef33 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -31,6 +31,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-50045.patch \ file://CVE-2026-50046.patch \ file://CVE-2026-50243.patch \ + file://CVE-2026-50248.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:21 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97911 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8A1CDC88E41 for ; Thu, 10 Sep 2026 23:10:47 +0000 (UTC) Received: from mail-pj1-f49.google.com (mail-pj1-f49.google.com [209.85.216.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27854.1789081845318945091 for ; Thu, 10 Sep 2026 16:10:45 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=GbcthewB; spf=pass (domain: gmail.com, ip: 209.85.216.49, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f49.google.com with SMTP id 98e67ed59e1d1-3969e82ff8fso359331a91.0 for ; Thu, 10 Sep 2026 16:10:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081845; x=1789686645; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jGQBDLMKQSSAWZFPZuN5XivWaTxllzuRWNuh+ZBdkQs=; b=GbcthewB/mg3pMTSTmT9AIU/539U2Cwol/I4gF3o0/isXrHOlrH3t+gvqR/REn0sn8 aHPRkjR3exZPMF2lx78FbPvMmlfyVBJOqRMrsbfNx1ueGyuqV0gPISyAs0hhKHpuXgsn 86Du/2EhB57XFh7aVVUxJDJiZwXKRYcMcKH9o/3pNSxVZX8nFNlEZpLIOzz9boYErF70 6ACkloxWIXGjvXF9SoAHpDt0gW1J5Wv5o72xsZMuthrc7zf6ZUtq8V+HvksKCerkCoU8 SIOgo2GyMd3NcUNz/6VnpCjQufiE04NQWnGkFxYWJDyvXoq1f2K/xBQREd4OUyDKtLig 7zIA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081845; x=1789686645; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=jGQBDLMKQSSAWZFPZuN5XivWaTxllzuRWNuh+ZBdkQs=; b=tJQBkOmtutr2a+zxFLjT+YC9/n85mqDxQVcvQZsSvL3W45TIAbAp9wJg3lSBLE65Hw 4lInWIPxzHaNLFCwtj3xCmeW1bWPl+i3O7CzjOE0lv2KnxKEYlS9iUrhzxUNF6cXQ9Ul 9E9v/aajg0SHbUAfL2DsjYhtWZb6kyT3jXm3J1mfeWZVVVLpX3zPLJtTopaFqmRPVqQv TGeTOO1DEAO74pinKXfBJJbn+CVfsvE4zEn4PBpdzd8jfahmYVBvuaTjA+AXSNT0TpTi n8GCp0T+QPtPt27x3bnjxdAKbEpnJNfSFzpJC5ao6Kzl71VtHY7xyFWmqbfs2yLa+7P5 8SUg== X-Gm-Message-State: AFuF++kMV4+m81kSmdqetrnmvlgXGv2Eu5fPQNFkdytUw5Z0ZlCDD/NX oDNhiRUrSzNpUq/15rv51avfetguXtA5nIiMJZZ+WKmwitzPGBQods8h768Q5Q== X-Gm-Gg: AYBFou1PKEzLv0s3SuJ4PltyU7DwzJbzuLZVs1vY88Bvj2Dd1sOe+eVCPgck8NBr4dH bQgRC/b85xBDQ8bqOiTKkUSBpI4VbCsvfv0EyWACEKmwsWEhCyMLbzGIlPjriFeMFVZaYHgMejF cV9q2LbqrHELaVqqbbR71fePWgaTVMKKl0wCkDvSX31N833UtfAgTOkFKqLrRS5xMr5DN5uIBOU vEUnDibrEDQ6zxDUCw5Hv9IGwvT0aGsbqX/ZA08Yod+ng8WimvTtoCxJKAvKzUpLVFfrM4bTf1Z ULhzV+8PmYeQl5f9GW1gnvtnj0rgOJv07pToxUyfAnRFYNRFuI/fQC9/K71Hd1uODIeYB4nQdyP v3tUqfDBXTgoJO1u5mD3zKyjINM+sR7fnjntIXewIQWpUsYfb3O541z/LTD80fYzis+yqKsDVgN pjJAqbRVUNUv+tZ6Q5Ug0gl0e3ZcOlC9S9wou+4x/hpaZh6WBkBHPFoRXstOND8VW0T0qQnj+Vl 5BxSOppRSROhfMelnUK5ME= X-Received: by 2002:a17:90b:2d03:b0:38e:67e1:15b with SMTP id 98e67ed59e1d1-39d9bc3f8c8mr1591252a91.6.1789081844629; Thu, 10 Sep 2026 16:10:44 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:44 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 22/32] unbound: patch CVE-2026-50251 Date: Fri, 11 Sep 2026 11:09:21 +1200 Message-ID: <20260910230932.173913-22-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:47 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129940 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-50251 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-50251.patch | 72 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 73 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-50251.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-50251.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50251.patch new file mode 100644 index 0000000000..5800ea8572 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50251.patch @@ -0,0 +1,72 @@ +From 2a514d577f035b1473d34201290be4394c732ff7 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:15:02 +0200 +Subject: [PATCH] - Fix CVE-2026-50251, Attacker supplied `0.0.0.0`/`::` glue + triggers defensive full-cache flush. Thanks to Qifan Zhang, Palo Alto + Networks, for the report. + +(cherry picked from commit e180b06298d8d39a764d3c5d4d4aca472c3a97d7) + +CVE: CVE-2026-50251 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/e180b06298d8d39a764d3c5d4d4aca472c3a97d7] + +Signed-off-by: Ankur Tyagi +--- + doc/unbound.conf.rst | 7 +++++++ + iterator/iter_donotq.c | 12 ++++++++++++ + testdata/dns_error_reporting.rpl | 1 + + 3 files changed, 20 insertions(+) + +diff --git a/doc/unbound.conf.rst b/doc/unbound.conf.rst +index d83816c6f..ca96a4411 100644 +--- a/doc/unbound.conf.rst ++++ b/doc/unbound.conf.rst +@@ -1954,6 +1954,13 @@ These options are part of the **server:** clause. + flushing away any poison. + A value of 10 million is suggested. + ++ It is useful to add 0.0.0.0/8 and '::' to the ++ :ref:`do-not-query-address` list. ++ Otherwise they may be answered, from localhost, and the different source ++ makes an unwanted reply that unnecessarily ticks up. ++ The :ref:`do-not-query-localhost` ++ option includes them, the zero subnets, when it is enabled. ++ + Default: 0 (disabled) + + +diff --git a/iterator/iter_donotq.c b/iterator/iter_donotq.c +index 40ffb45c4..7eecf1354 100644 +--- a/iterator/iter_donotq.c ++++ b/iterator/iter_donotq.c +@@ -132,6 +132,18 @@ donotq_apply_cfg(struct iter_donotq* dq, struct config_file* cfg) + if(cfg->do_ip6) { + if(!donotq_str_cfg(dq, "::1")) + return 0; ++ if(!donotq_str_cfg(dq, "::ffff:127.0.0.0/104")) ++ return 0; ++ } ++ /* RFC 1122 3.2.1.3 / RFC 6890 / RFC 4291 2.5.2: not valid as ++ * destination; on Linux these route to the local host. */ ++ if(!donotq_str_cfg(dq, "0.0.0.0/8")) ++ return 0; ++ if(cfg->do_ip6) { ++ if(!donotq_str_cfg(dq, "::")) ++ return 0; ++ if(!donotq_str_cfg(dq, "::ffff:0:0/96")) ++ return 0; + } + } + addr_tree_init_parents(&dq->tree); +diff --git a/testdata/dns_error_reporting.rpl b/testdata/dns_error_reporting.rpl +index f1fac12a2..22175cade 100644 +--- a/testdata/dns_error_reporting.rpl ++++ b/testdata/dns_error_reporting.rpl +@@ -12,6 +12,7 @@ server: + ede: no # It is not needed for dns-error-reporting; only for clients to receive EDEs + dns-error-reporting: yes + do-ip6: no ++ do-not-query-localhost: no + + stub-zone: + name: domain diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index b6b6ecef33..0a511f767e 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -32,6 +32,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-50046.patch \ file://CVE-2026-50243.patch \ file://CVE-2026-50248.patch \ + file://CVE-2026-50251.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:22 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97916 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id BAF39C79FBB for ; Thu, 10 Sep 2026 23:10:57 +0000 (UTC) Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27855.1789081848661483814 for ; Thu, 10 Sep 2026 16:10:48 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=ZaYk1X/n; spf=pass (domain: gmail.com, ip: 209.85.216.44, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-398a5aad413so281638a91.3 for ; Thu, 10 Sep 2026 16:10:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081848; x=1789686648; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dv8uJ5y+EY7B/OEoNJgxssQQ/s3ZYR8Xqw3kVMqmF/0=; b=ZaYk1X/nbqPNnlXs6GA6WTwVUZ4Oqh/VjPOgwsR0kVyjAt/zXD+2YtZK4EqRn1WyY8 1T1/HaiiiQlACfQHIGj/rNy96UHda/8Oo3SswtgsHngEQWjT4erzgp8SLLCEsJr50Yez +5du0KKIMgfbcPPuLZV6Z7blWH10j5FNyIqu2P/f22QXWt1GCOHtT2qPSL3NsV9uEn1n JmoDaAOMphUmWkRPf+7T4iufE7Iu/iYliPDXBW8HtuTZbxf5F/8RKKD6e5KcZHoLJXpS RFX/ca8q3zXsNcdPtX6Db0f9OHwKCqqKzpieIyYpJXBjqO3mR2FJZDDvKk0zTmrrh+54 3Fkg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081848; x=1789686648; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dv8uJ5y+EY7B/OEoNJgxssQQ/s3ZYR8Xqw3kVMqmF/0=; b=Q/NDbRUcPCNn5zDeCeF/ckxuNfqhKb633iXQhb1WPW+5P3CM43LIN/p7KGh73WtKDk fAR1O87VB1h/xXK6OehuyqdJ+u4IbaOY5X3TgYoTLGYyrCa8ZFyuR5MqZRCy2ME6ASJW nbZjQ8ZXo+Ko4XR5sSPx78inMY2HTPp397cOw8ogXMfi3KtQwNObVXx0b0EG/yEwF1qv x/k5vrSmlX2muWBGtF2ixoqEhX5ctuoL8AJWWpRgoZ9XDEqh08P2SaDzr4FFgs3e30Ov GSN8rBubyUTKdZ3vq5vhTd5+JEqj9IhbYYWxF105ZMuP0lRC7nOm6WsRHQeaoqfso1Qg z2wg== X-Gm-Message-State: AFuF++lMmKpoIT3kQKtSNKlJdtbexiYcwzNSgOeZjP4FFgJi4z18O0SO BDmaCaHwuPtEJUdgOd+kGTO9//kTVQU22hT49N0ftuHUV64iAIi0hBX4ssfVfQ== X-Gm-Gg: AYBFou2JwtSTz+mHtomtkfarAQ7UAp3N5aVRvhYCfbsnMdwym/kSEAGrwKHTgEqDGQH /Tb1i+ZMUS3xNo8VAue7nn/LqMx3q4dPcWitGS2z/9SNbLgJm1n2R9sKIGuoFRmPnrZjm4fPZcu qByuN78x147RCaRmheANprpZFy1GFtwumNgvo9X6AQkAWgrzHYE1V1yLCYMOVh7lAdEdzFmA0Cv 0NMCOaQFQfyfQJdq1Sgf3UwifHL9MUeJBcaApsjwr3fi1d7sH/ZP2VI/Q97Ubcjzuv83tcjtxiC 6Z4e2SrjwiVfwPDa+AsJ6Ej534wh9tmJyyU2uw8FOPASyuTJIr+HoAxpAz1zcjVddG52MsjwS1c iwB0W/RGuqUNdb0L2CU9Ufp2yobyRUqTwzC/AnBLH8uKaGD17pEsNlRAHztP04V/wiiuzebr2Cz Du89hma48PRj02Z3ScSioKHvCtxtsaoV2FakTXRFGCR8m7koxY+3In3XGpBbVPHyotGoNfFSMMG IX0F453A7A9i7DSwpLTe6s= X-Received: by 2002:a17:90b:3e50:b0:38e:9ef9:eb97 with SMTP id 98e67ed59e1d1-39d9c1d8f30mr2029716a91.16.1789081847583; Thu, 10 Sep 2026 16:10:47 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.45 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:47 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 23/32] unbound: patch CVE-2026-50252 Date: Fri, 11 Sep 2026 11:09:22 +1200 Message-ID: <20260910230932.173913-23-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129941 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-50252 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-50252.patch | 1294 +++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 1295 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-50252.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-50252.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50252.patch new file mode 100644 index 0000000000..4e31d1050f --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-50252.patch @@ -0,0 +1,1294 @@ +From b1570f42273537ca1d12da0e7c15e66070ebaa68 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:15:31 +0200 +Subject: [PATCH] - Fix CVE-2026-50252, Possible cache poisoning attack by + mapping source port population per thread. Thanks to Inbal Schussheim and + Amit Klein, Hebrew University, for the report. + +(cherry picked from commit 804cff4c152a121961b04605f75132370fc80df4) + +CVE: CVE-2026-50252 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/804cff4c152a121961b04605f75132370fc80df4] + +Signed-off-by: Ankur Tyagi +--- + daemon/daemon.c | 12 +- + daemon/daemon.h | 3 + + daemon/worker.c | 15 +- + daemon/worker.h | 8 +- + libunbound/libworker.c | 13 +- + libunbound/libworker.h | 3 + + services/outside_network.c | 376 ++++++++++++++++++++++++++++++------- + services/outside_network.h | 105 ++++++++++- + testcode/fake_event.c | 21 ++- + testcode/unittcpreuse.c | 276 +++++++++++++++++++++++++++ + 10 files changed, 728 insertions(+), 104 deletions(-) + +diff --git a/daemon/daemon.c b/daemon/daemon.c +index f882bb9ad..a2f1ec7d4 100644 +--- a/daemon/daemon.c ++++ b/daemon/daemon.c +@@ -79,6 +79,7 @@ + #include "util/tcp_conn_limit.h" + #include "util/edns.h" + #include "services/listen_dnsport.h" ++#include "services/outside_network.h" + #include "services/cache/rrset.h" + #include "services/cache/infra.h" + #include "services/localzone.h" +@@ -556,6 +557,10 @@ daemon_create_workers(struct daemon* daemon) + fatal_exit("out of memory during daemon init"); + numport = daemon_get_shufport(daemon, shufport); + verbose(VERB_ALGO, "total of %d outgoing ports available", numport); ++ if(!(daemon->shared_ports = shared_ports_create(daemon->cfg->out_ifs, ++ daemon->cfg->num_out_ifs, daemon->cfg->do_ip4, ++ daemon->cfg->do_ip6, shufport, numport))) ++ fatal_exit("could not setup shared ports: out of memory"); + + #ifdef HAVE_NGTCP2 + daemon->doq_table = doq_table_create(daemon->cfg, daemon->rand); +@@ -584,10 +589,7 @@ daemon_create_workers(struct daemon* daemon) + #endif + } + for(i=0; inum; i++) { +- if(!(daemon->workers[i] = worker_create(daemon, i, +- shufport+numport*i/daemon->num, +- numport*(i+1)/daemon->num - numport*i/daemon->num))) +- /* the above is not ports/numthr, due to rounding */ ++ if(!(daemon->workers[i] = worker_create(daemon, i))) + fatal_exit("could not create worker"); + } + /* create per-worker alloc caches if not reusing existing ones. */ +@@ -908,6 +910,8 @@ daemon_cleanup(struct daemon* daemon) + if(!daemon->reuse_cache || daemon->need_to_exit) + daemon_clear_allocs(daemon); + daemon->num = 0; ++ shared_ports_delete(daemon->shared_ports); ++ daemon->shared_ports = NULL; + #ifdef USE_DNSTAP + dt_delete(daemon->dtenv); + daemon->dtenv = NULL; +diff --git a/daemon/daemon.h b/daemon/daemon.h +index 2295761ab..fb7c9f373 100644 +--- a/daemon/daemon.h ++++ b/daemon/daemon.h +@@ -62,6 +62,7 @@ struct doq_table; + struct cookie_secrets; + struct fast_reload_thread; + struct fast_reload_printq; ++struct shared_ports; + + #include "dnstap/dnstap_config.h" + #ifdef USE_DNSTAP +@@ -97,6 +98,8 @@ struct daemon { + int rc_port; + /** listening ports for remote control */ + struct listen_port* rc_ports; ++ /** the shared ports structure, with random ports numbers. */ ++ struct shared_ports* shared_ports; + /** remote control connections management (for first worker) */ + struct daemon_remote* rc; + /** ssl context for listening to dnstcp over ssl */ +diff --git a/daemon/worker.c b/daemon/worker.c +index b9fac0406..36ccff859 100644 +--- a/daemon/worker.c ++++ b/daemon/worker.c +@@ -2144,23 +2144,16 @@ void worker_probe_timer_cb(void* arg) + } + + struct worker* +-worker_create(struct daemon* daemon, int id, int* ports, int n) ++worker_create(struct daemon* daemon, int id) + { + unsigned int seed; + struct worker* worker = (struct worker*)calloc(1, + sizeof(struct worker)); + if(!worker) + return NULL; +- worker->numports = n; +- worker->ports = (int*)memdup(ports, sizeof(int)*n); +- if(!worker->ports) { +- free(worker); +- return NULL; +- } + worker->daemon = daemon; + worker->thread_num = id; + if(!(worker->cmd = tube_create())) { +- free(worker->ports); + free(worker); + return NULL; + } +@@ -2168,7 +2161,6 @@ worker_create(struct daemon* daemon, int id, int* ports, int n) + if(!(worker->rndstate = ub_initstate(daemon->rand))) { + log_err("could not init random numbers."); + tube_delete(worker->cmd); +- free(worker->ports); + free(worker); + return NULL; + } +@@ -2270,14 +2262,14 @@ worker_init(struct worker* worker, struct config_file *cfg, + cfg->out_ifs, cfg->num_out_ifs, cfg->do_ip4, cfg->do_ip6, + cfg->do_tcp?cfg->outgoing_num_tcp:0, cfg->ip_dscp, + worker->daemon->env->infra_cache, worker->rndstate, +- cfg->use_caps_bits_for_id, worker->ports, worker->numports, ++ cfg->use_caps_bits_for_id, + cfg->unwanted_threshold, cfg->outgoing_tcp_mss, + &worker_alloc_cleanup, worker, + cfg->do_udp || cfg->udp_upstream_without_downstream, + worker->daemon->connect_dot_sslctx, cfg->delay_close, + cfg->tls_use_sni, dtenv, cfg->udp_connect, + cfg->max_reuse_tcp_queries, cfg->tcp_reuse_timeout, +- cfg->tcp_auth_query_timeout); ++ cfg->tcp_auth_query_timeout, worker->daemon->shared_ports); + if(!worker->back) { + log_err("could not create outgoing sockets"); + worker_delete(worker); +@@ -2428,7 +2420,6 @@ worker_delete(struct worker* worker) + tube_delete(worker->cmd); + comm_timer_delete(worker->stat_timer); + comm_timer_delete(worker->env.probe_timer); +- free(worker->ports); + if(worker->thread_num == 0) { + #ifdef UB_ON_WINDOWS + wsvc_desetup_worker(worker); +diff --git a/daemon/worker.h b/daemon/worker.h +index b7bb52fd7..37f3728ef 100644 +--- a/daemon/worker.h ++++ b/daemon/worker.h +@@ -104,10 +104,6 @@ struct worker { + struct listen_dnsport* front; + /** the backside outside network interface to the auth servers */ + struct outside_network* back; +- /** ports to be used by this worker. */ +- int* ports; +- /** number of ports for this worker */ +- int numports; + /** the signal handler */ + struct comm_signal* comsig; + /** commpoint to listen to commands. */ +@@ -146,11 +142,9 @@ struct worker { + * with backpointers only. Use worker_init on it later. + * @param daemon: the daemon that this worker thread is part of. + * @param id: the thread number from 0.. numthreads-1. +- * @param ports: the ports it is allowed to use, array. +- * @param n: the number of ports. + * @return: the new worker or NULL on alloc failure. + */ +-struct worker* worker_create(struct daemon* daemon, int id, int* ports, int n); ++struct worker* worker_create(struct daemon* daemon, int id); + + /** + * Initialize worker. +diff --git a/libunbound/libworker.c b/libunbound/libworker.c +index 6e7244c03..d70527f59 100644 +--- a/libunbound/libworker.c ++++ b/libunbound/libworker.c +@@ -105,6 +105,7 @@ libworker_delete_env(struct libworker* w) + SSL_CTX_free(w->sslctx); + #endif + outside_network_delete(w->back); ++ shared_ports_delete(w->shared_ports); + } + + /** delete libworker struct */ +@@ -219,17 +220,25 @@ libworker_setup(struct ub_ctx* ctx, int is_bg, struct ub_event_base* eb) + libworker_delete(w); + return NULL; + } ++ if(!(w->shared_ports = shared_ports_create(cfg->out_ifs, ++ cfg->num_out_ifs, cfg->do_ip4, cfg->do_ip6, ports, numports))) { ++ if(!w->is_bg || w->is_bg_thread) { ++ lock_basic_unlock(&ctx->cfglock); ++ } ++ libworker_delete(w); ++ return NULL; ++ } + w->back = outside_network_create(w->base, cfg->msg_buffer_size, + (size_t)cfg->outgoing_num_ports, cfg->out_ifs, + cfg->num_out_ifs, cfg->do_ip4, cfg->do_ip6, + cfg->do_tcp?cfg->outgoing_num_tcp:0, cfg->ip_dscp, + w->env->infra_cache, w->env->rnd, cfg->use_caps_bits_for_id, +- ports, numports, cfg->unwanted_threshold, ++ cfg->unwanted_threshold, + cfg->outgoing_tcp_mss, &libworker_alloc_cleanup, w, + cfg->do_udp || cfg->udp_upstream_without_downstream, w->sslctx, + cfg->delay_close, cfg->tls_use_sni, NULL, cfg->udp_connect, + cfg->max_reuse_tcp_queries, cfg->tcp_reuse_timeout, +- cfg->tcp_auth_query_timeout); ++ cfg->tcp_auth_query_timeout, w->shared_ports); + w->env->outnet = w->back; + if(!w->is_bg || w->is_bg_thread) { + lock_basic_unlock(&ctx->cfglock); +diff --git a/libunbound/libworker.h b/libunbound/libworker.h +index 42aa5bae3..f527cb093 100644 +--- a/libunbound/libworker.h ++++ b/libunbound/libworker.h +@@ -60,6 +60,7 @@ struct tube; + struct sldns_buffer; + struct ub_event_base; + struct query_info; ++struct shared_ports; + + /** + * The library-worker status structure +@@ -84,6 +85,8 @@ struct libworker { + struct comm_base* base; + /** the backside outside network interface to the auth servers */ + struct outside_network* back; ++ /** shared ports structure */ ++ struct shared_ports* shared_ports; + /** random() table for this worker. */ + struct ub_randstate* rndstate; + /** sslcontext for SSL wrapped DNS over TCP queries */ +diff --git a/services/outside_network.c b/services/outside_network.c +index bc65d36f7..140ebec1b 100644 +--- a/services/outside_network.c ++++ b/services/outside_network.c +@@ -1434,7 +1434,7 @@ portcomm_loweruse(struct outside_network* outnet, struct port_comm* pc) + pif = pc->pif; + log_assert(pif->inuse > 0); + #ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- pif->avail_ports[pif->avail_total - pif->inuse] = pc->number; ++ shared_ports_return_port(outnet->shared_ports, pif->shpif, pc->number); + #endif + pif->inuse--; + pif->out[pc->index] = pif->out[pif->inuse]; +@@ -1648,19 +1648,19 @@ create_pending_tcp(struct outside_network* outnet, size_t bufsize) + } + + /** setup an outgoing interface, ready address */ +-static int setup_if(struct port_if* pif, const char* addrstr, +- int* avail, int numavail, size_t numfd) ++static int setup_if(struct port_if* pif, const char* addrstr, size_t numfd, ++ struct shared_ports* shp) + { +-#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- pif->avail_total = numavail; +- pif->avail_ports = (int*)memdup(avail, (size_t)numavail*sizeof(int)); +- if(!pif->avail_ports) +- return 0; +-#endif + if(!ipstrtoaddr(addrstr, UNBOUND_DNS_PORT, &pif->addr, &pif->addrlen) && + !netblockstrtoaddr(addrstr, UNBOUND_DNS_PORT, + &pif->addr, &pif->addrlen, &pif->pfxlen)) + return 0; ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ pif->shpif = shared_ports_find_if(shp, &pif->addr, pif->addrlen, ++ pif->pfxlen); ++#else ++ (void)shp; ++#endif + pif->maxout = (int)numfd; + pif->inuse = 0; + pif->out = (struct port_comm**)calloc(numfd, +@@ -1674,12 +1674,12 @@ struct outside_network* + outside_network_create(struct comm_base *base, size_t bufsize, + size_t num_ports, char** ifs, int num_ifs, int do_ip4, + int do_ip6, size_t num_tcp, int dscp, struct infra_cache* infra, +- struct ub_randstate* rnd, int use_caps_for_id, int* availports, +- int numavailports, size_t unwanted_threshold, int tcp_mss, ++ struct ub_randstate* rnd, int use_caps_for_id, ++ size_t unwanted_threshold, int tcp_mss, + void (*unwanted_action)(void*), void* unwanted_param, int do_udp, + void* sslctx, int delayclose, int tls_use_sni, struct dt_env* dtenv, + int udp_connect, int max_reuse_tcp_queries, int tcp_reuse_timeout, +- int tcp_auth_query_timeout) ++ int tcp_auth_query_timeout, struct shared_ports* shared_ports) + { + struct outside_network* outnet = (struct outside_network*) + calloc(1, sizeof(struct outside_network)); +@@ -1714,6 +1714,7 @@ outside_network_create(struct comm_base *base, size_t bufsize, + outnet->do_udp = do_udp; + outnet->tcp_mss = tcp_mss; + outnet->ip_dscp = dscp; ++ outnet->shared_ports = shared_ports; + #ifndef S_SPLINT_S + if(delayclose) { + outnet->delayclose = 1; +@@ -1724,7 +1725,7 @@ outside_network_create(struct comm_base *base, size_t bufsize, + if(udp_connect) { + outnet->udp_connect = 1; + } +- if(numavailports == 0 || num_ports == 0) { ++ if(num_ports == 0) { + log_err("no outgoing ports available"); + outside_network_delete(outnet); + return NULL; +@@ -1785,13 +1786,13 @@ outside_network_create(struct comm_base *base, size_t bufsize, + /* allocate interfaces */ + if(num_ifs == 0) { + if(do_ip4 && !setup_if(&outnet->ip4_ifs[0], "0.0.0.0", +- availports, numavailports, num_ports)) { ++ num_ports, outnet->shared_ports)) { + log_err("malloc failed"); + outside_network_delete(outnet); + return NULL; + } + if(do_ip6 && !setup_if(&outnet->ip6_ifs[0], "::", +- availports, numavailports, num_ports)) { ++ num_ports, outnet->shared_ports)) { + log_err("malloc failed"); + outside_network_delete(outnet); + return NULL; +@@ -1802,7 +1803,7 @@ outside_network_create(struct comm_base *base, size_t bufsize, + for(i=0; iip6_ifs[done_6], ifs[i], +- availports, numavailports, num_ports)){ ++ num_ports, outnet->shared_ports)){ + log_err("malloc failed"); + outside_network_delete(outnet); + return NULL; +@@ -1811,7 +1812,7 @@ outside_network_create(struct comm_base *base, size_t bufsize, + } + if(!str_is_ip6(ifs[i]) && do_ip4) { + if(!setup_if(&outnet->ip4_ifs[done_4], ifs[i], +- availports, numavailports, num_ports)){ ++ num_ports, outnet->shared_ports)){ + log_err("malloc failed"); + outside_network_delete(outnet); + return NULL; +@@ -1889,9 +1890,6 @@ outside_network_delete(struct outside_network* outnet) + comm_point_delete(pc->cp); + free(pc); + } +-#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- free(outnet->ip4_ifs[i].avail_ports); +-#endif + free(outnet->ip4_ifs[i].out); + } + free(outnet->ip4_ifs); +@@ -1905,9 +1903,6 @@ outside_network_delete(struct outside_network* outnet) + comm_point_delete(pc->cp); + free(pc); + } +-#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- free(outnet->ip6_ifs[i].avail_ports); +-#endif + free(outnet->ip6_ifs[i].out); + } + free(outnet->ip6_ifs); +@@ -2113,7 +2108,10 @@ static int + select_ifport(struct outside_network* outnet, struct pending* pend, + int num_if, struct port_if* ifs) + { +- int my_if, my_port, fd, portno, inuse, tries=0; ++ int my_if, fd, portno, inuse, tries=0; ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ int reused; ++#endif + struct port_if* pif; + /* randomly select interface and port */ + if(num_if == 0) { +@@ -2127,37 +2125,35 @@ select_ifport(struct outside_network* outnet, struct pending* pend, + my_if = ub_random_max(outnet->rnd, num_if); + pif = &ifs[my_if]; + #ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- if(outnet->udp_connect) { +- /* if we connect() we cannot reuse fds for a port */ +- if(pif->inuse >= pif->avail_total) { +- tries++; +- if(tries < MAX_PORT_RETRY) +- continue; +- log_err("failed to find an open port, drop msg"); +- return 0; +- } +- my_port = pif->inuse + ub_random_max(outnet->rnd, +- pif->avail_total - pif->inuse); +- } else { +- my_port = ub_random_max(outnet->rnd, pif->avail_total); +- if(my_port < pif->inuse) { +- /* port already open */ +- pend->pc = pif->out[my_port]; +- verbose(VERB_ALGO, "using UDP if=%d port=%d", +- my_if, pend->pc->number); +- break; +- } ++ if(!shared_ports_fetch_random(outnet->shared_ports, ++ pif->shpif, outnet->rnd, outnet->udp_connect, ++ pif->inuse, &portno, &reused)) { ++ tries++; ++ if(tries < MAX_PORT_RETRY) ++ continue; ++ log_err("failed to find an open port, drop msg"); ++ return 0; ++ } ++ if(reused) { ++ /* port already open */ ++ log_assert(portno < pif->inuse); ++ pend->pc = pif->out[portno]; ++ verbose(VERB_ALGO, "using UDP if=%d port=%d", ++ my_if, pend->pc->number); ++ break; + } +- /* try to open new port, if fails, loop to try again */ +- log_assert(pif->inuse < pif->maxout); +- portno = pif->avail_ports[my_port - pif->inuse]; + #else +- my_port = portno = 0; ++ portno = 0; + #endif ++ /* try to open new port, if fails, loop to try again */ + fd = udp_sockport(&pif->addr, pif->addrlen, pif->pfxlen, + portno, &inuse, outnet->rnd, outnet->ip_dscp); + if(fd == -1 && !inuse) { + /* nonrecoverable error making socket */ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ shared_ports_return_port(outnet->shared_ports, ++ pif->shpif, portno); ++#endif + return 0; + } + if(fd != -1) { +@@ -2174,6 +2170,11 @@ select_ifport(struct outside_network* outnet, struct pending* pend, + pend->addrlen); + } + sock_close(fd); ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ shared_ports_return_port( ++ outnet->shared_ports, ++ pif->shpif, portno); ++#endif + return 0; + } + } +@@ -2191,14 +2192,14 @@ select_ifport(struct outside_network* outnet, struct pending* pend, + + /* grab port in interface */ + pif->out[pif->inuse] = pend->pc; +-#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- pif->avail_ports[my_port - pif->inuse] = +- pif->avail_ports[pif->avail_total-pif->inuse-1]; +-#endif + pif->inuse++; + break; + } + /* failed, already in use */ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ shared_ports_return_port(outnet->shared_ports, pif->shpif, ++ portno); ++#endif + verbose(VERB_QUERY, "port %d in use, trying another", portno); + tries++; + if(tries == MAX_PORT_RETRY) { +@@ -3589,13 +3590,16 @@ fd_for_dest(struct outside_network* outnet, struct sockaddr_storage* to_addr, + { + struct sockaddr_storage* addr; + socklen_t addrlen; +- int i, try, pnum, dscp; ++ int i, try, dscp; + struct port_if* pif; + + /* create fd */ + dscp = outnet->ip_dscp; + for(try = 0; try<1000; try++) { + int port = 0; ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ int reused = 0; ++#endif + int freebind = 0; + int noproto = 0; + int inuse = 0; +@@ -3624,16 +3628,18 @@ fd_for_dest(struct outside_network* outnet, struct sockaddr_storage* to_addr, + addr = &pif->addr; + addrlen = pif->addrlen; + #ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- pnum = ub_random_max(outnet->rnd, pif->avail_total); +- if(pnum < pif->inuse) { +- /* port already open */ +- port = pif->out[pnum]->number; +- } else { +- /* unused ports in start part of array */ +- port = pif->avail_ports[pnum - pif->inuse]; ++ if(!shared_ports_fetch_random(outnet->shared_ports, ++ pif->shpif, outnet->rnd, 0, pif->inuse, ++ &port, &reused)) { ++ /* try again, perhaps another interface. */ ++ continue; ++ } ++ if(reused) { ++ log_assert(port < pif->inuse); ++ port = pif->out[port]->number; + } + #else +- pnum = port = 0; ++ port = 0; + #endif + if(addr_is_ip6(to_addr, to_addrlen)) { + struct sockaddr_in6 sa = *(struct sockaddr_in6*)addr; +@@ -3648,6 +3654,14 @@ fd_for_dest(struct outside_network* outnet, struct sockaddr_storage* to_addr, + (struct sockaddr*)addr, addrlen, 1, &inuse, &noproto, + 0, 0, 0, NULL, 0, freebind, 0, dscp); + } ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ if(!reused) { ++ /* Return the port to the pool, since the caller does ++ * not keep track of it, also have done fd, and bind. */ ++ shared_ports_return_port(outnet->shared_ports, ++ pif->shpif, port); ++ } ++#endif + if(fd != -1) { + return fd; + } +@@ -3878,11 +3892,7 @@ if_get_mem(struct port_if* pif) + { + size_t s; + int i; +- s = sizeof(*pif) + +-#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- sizeof(int)*pif->avail_total + +-#endif +- sizeof(struct port_comm*)*pif->maxout; ++ s = sizeof(*pif) + sizeof(struct port_comm*)*pif->maxout; + for(i=0; iinuse; i++) + s += sizeof(*pif->out[i]) + + comm_point_get_mem(pif->out[i]->cp); +@@ -3970,3 +3980,237 @@ serviced_get_mem(struct serviced_query* sq) + return s; + } + ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++/** Setup shared port interface */ ++static int shared_ports_setup_if(struct shared_ports_if* shpif, char* str, ++ int* availports, int numavailports) ++{ ++ shpif->avail_ports = (int*)memdup(availports, ++ (size_t)numavailports*sizeof(int)); ++ if(!shpif->avail_ports) ++ return 0; ++ shpif->avail_total = numavailports; ++ shpif->inuse = 0; ++ shpif->pfxlen = 0; ++ if(!ipstrtoaddr(str, UNBOUND_DNS_PORT, &shpif->addr, &shpif->addrlen) && ++ !netblockstrtoaddr(str, UNBOUND_DNS_PORT, &shpif->addr, ++ &shpif->addrlen, &shpif->pfxlen)) ++ return 0; ++ return 1; ++} ++#endif ++ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++/** Allocate shared ports interfaces */ ++static int shared_ports_alloc_ifs(struct shared_ports* shp, char** ifs, ++ int num_ifs, int do_ip4, int do_ip6, int* availports, ++ int numavailports) ++{ ++#ifndef INET6 ++ do_ip6 = 0; ++#endif ++ calc_num46(ifs, num_ifs, do_ip4, do_ip6, ++ &shp->num_ip4, &shp->num_ip6); ++ if(shp->num_ip4 != 0) { ++ if(!(shp->ip4_ifs = (struct shared_ports_if*)calloc( ++ (size_t)shp->num_ip4, ++ sizeof(struct shared_ports_if)))) ++ return 0; ++ } ++ if(shp->num_ip6 != 0) { ++ if(!(shp->ip6_ifs = (struct shared_ports_if*)calloc( ++ (size_t)shp->num_ip6, ++ sizeof(struct shared_ports_if)))) ++ return 0; ++ } ++ if(num_ifs == 0) { ++ if(do_ip4 && !shared_ports_setup_if(&shp->ip4_ifs[0], ++ "0.0.0.0", availports, numavailports)) ++ return 0; ++ if(do_ip6 && !shared_ports_setup_if(&shp->ip6_ifs[0], ++ "::", availports, numavailports)) ++ return 0; ++ } else { ++ size_t done_4 = 0, done_6 = 0; ++ int i; ++ for(i=0; iip6_ifs[done_6], ++ ifs[i], availports, numavailports)) ++ return 0; ++ done_6++; ++ } ++ if(!str_is_ip6(ifs[i]) && do_ip4) { ++ if(!shared_ports_setup_if(&shp->ip4_ifs[done_4], ++ ifs[i], availports, numavailports)) ++ return 0; ++ done_4++; ++ } ++ } ++ } ++ return 1; ++} ++#endif ++ ++struct shared_ports* shared_ports_create(char** ifs, int num_ifs, int do_ip4, ++ int do_ip6, int* availports, int numavailports) ++{ ++ struct shared_ports* shp = calloc(1, sizeof(*shp)); ++ if(!shp) { ++ log_err("malloc failed"); ++ return NULL; ++ } ++ lock_basic_init(&shp->lock); ++ lock_protect(&shp->lock, shp, sizeof(*shp)); ++ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ /* Allocate interfaces */ ++ if(!shared_ports_alloc_ifs(shp, ifs, num_ifs, do_ip4, do_ip6, ++ availports, numavailports)) { ++ log_err("malloc failed"); ++ shared_ports_delete(shp); ++ return NULL; ++ } ++#else ++ (void)ifs; (void)num_ifs; (void)do_ip4; (void)do_ip6; ++ (void)availports; (void)numavailports; ++#endif ++ return shp; ++} ++ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++/** Delete shared ports interface structure */ ++static void shared_ports_if_delete(struct shared_ports_if* shpif) ++{ ++ if(!shpif) ++ return; ++ free(shpif->avail_ports); ++} ++#endif ++ ++void shared_ports_delete(struct shared_ports* shp) ++{ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ int i; ++#endif ++ if(!shp) ++ return; ++ lock_basic_destroy(&shp->lock); ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ for(i=0; inum_ip4; i++) { ++ shared_ports_if_delete(&shp->ip4_ifs[i]); ++ } ++ free(shp->ip4_ifs); ++ for(i=0; inum_ip6; i++) { ++ shared_ports_if_delete(&shp->ip6_ifs[i]); ++ } ++ free(shp->ip6_ifs); ++#endif ++ free(shp); ++} ++ ++struct shared_ports_if* shared_ports_find_if(struct shared_ports* shp, ++ struct sockaddr_storage* addr, socklen_t addrlen, int pfxlen) ++{ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ struct shared_ports_if* ret, *ifs = NULL; ++ int i, num_ifs = 0; ++ lock_basic_lock(&shp->lock); ++ if(addr_is_ip6(addr, addrlen)) { ++ ifs = shp->ip6_ifs; ++ num_ifs = shp->num_ip6; ++ } else { ++ ifs = shp->ip4_ifs; ++ num_ifs = shp->num_ip4; ++ } ++ for(i=0; ilock); ++ return ret; ++ } ++ } ++ lock_basic_unlock(&shp->lock); ++ return NULL; ++#else ++ (void)shp; (void)addr; (void)addrlen; (void)pfxlen; ++ return NULL; ++#endif ++} ++ ++int shared_ports_fetch_random(struct shared_ports* shp, ++ struct shared_ports_if* shpif, struct ub_randstate* rnd, ++ int udp_connect, int reusenum, int* port, int* reused) ++{ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ int portno = 0, my_port = 0; ++ if(!shpif) ++ return 0; ++ lock_basic_lock(&shp->lock); ++ if(udp_connect) { ++ /* if we connect() we cannot reuse fds for a port. */ ++ if(shpif->inuse >= shpif->avail_total) { ++ lock_basic_unlock(&shp->lock); ++ return 0; ++ } ++ my_port = ub_random_max(rnd, ++ shpif->avail_total - shpif->inuse); ++ } else { ++ /* select from free ports and open ports on this thread. */ ++ if(shpif->inuse >= shpif->avail_total) { ++ lock_basic_unlock(&shp->lock); ++ if(reusenum == 0) { ++ return 0; ++ } ++ my_port = ub_random_max(rnd, reusenum); ++ *port = my_port; ++ *reused = 1; ++ return 1; ++ } ++ my_port = ub_random_max(rnd, shpif->avail_total - shpif->inuse ++ + reusenum); ++ if(my_port < reusenum) { ++ /* port already open */ ++ lock_basic_unlock(&shp->lock); ++ *port = my_port; ++ *reused = 1; ++ return 1; ++ } ++ my_port -= reusenum; ++ } ++ log_assert(shpif->inuse < shpif->avail_total); ++ log_assert(my_port >= 0 && my_port < shpif->avail_total); ++ portno = shpif->avail_ports[my_port]; ++ shpif->avail_ports[my_port] = ++ shpif->avail_ports[shpif->avail_total-shpif->inuse-1]; ++ shpif->inuse++; ++ lock_basic_unlock(&shp->lock); ++ *port = portno; ++ *reused = 0; ++ return 1; ++#else ++ (void)shp; (void)shpif; (void)rnd; (void)udp_connect; ++ (void)reusenum; ++ *port = 0; ++ *reused = 0; ++ return 1; ++#endif ++} ++ ++void shared_ports_return_port(struct shared_ports* shp, ++ struct shared_ports_if* shpif, int port) ++{ ++#ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION ++ if(!shpif) ++ return; ++ lock_basic_lock(&shp->lock); ++ log_assert(shpif->inuse > 0); ++ shpif->avail_ports[shpif->avail_total - shpif->inuse] = port; ++ shpif->inuse--; ++ lock_basic_unlock(&shp->lock); ++#else ++ (void)shp; (void)shpif; (void)port; ++#endif ++} +diff --git a/services/outside_network.h b/services/outside_network.h +index 81ebfe3e2..e0095c49c 100644 +--- a/services/outside_network.h ++++ b/services/outside_network.h +@@ -66,6 +66,8 @@ struct module_env; + struct module_qstate; + struct query_info; + struct config_file; ++struct shared_ports; ++struct shared_ports_if; + + /** + * Send queries to outside servers and wait for answers from servers. +@@ -115,6 +117,9 @@ struct outside_network { + int udp_connect; + /** number of udp packets sent. */ + size_t num_udp_outgoing; ++ /** the shared ports structure, with random ports numbers. ++ * This is a reference to the member in the daemon structure. */ ++ struct shared_ports* shared_ports; + + /** array of outgoing IP4 interfaces */ + struct port_if* ip4_ifs; +@@ -207,11 +212,8 @@ struct port_if { + int pfxlen; + + #ifndef DISABLE_EXPLICIT_PORT_RANDOMISATION +- /** the available ports array. These are unused. +- * Only the first total-inuse part is filled. */ +- int* avail_ports; +- /** the total number of available ports (size of the array) */ +- int avail_total; ++ /** the shared port numbers for this interface. */ ++ struct shared_ports_if* shpif; + #endif + + /** array of the commpoints currently in use. +@@ -241,6 +243,42 @@ struct port_comm { + struct comm_point* cp; + }; + ++/** ++ * Shared ports, the list of ports shared across threads ++ */ ++struct shared_ports { ++ /** mutex on the ports */ ++ lock_basic_type lock; ++ /** array of IP4 interfaces */ ++ struct shared_ports_if* ip4_ifs; ++ /** number of outgoing IP4 interfaces */ ++ int num_ip4; ++ /** array of IP6 interfaces */ ++ struct shared_ports_if* ip6_ifs; ++ /** number of outgoing IP6 interfaces */ ++ int num_ip6; ++}; ++ ++/** ++ * Shared ports for an interface. ++ */ ++struct shared_ports_if { ++ /** address ready to allocate new socket (except port no). */ ++ struct sockaddr_storage addr; ++ /** length of addr field */ ++ socklen_t addrlen; ++ /** if a netblock, the prefix */ ++ int pfxlen; ++ ++ /** the available ports array. These are unused. ++ * Only the first total-inuse part is filled. */ ++ int* avail_ports; ++ /** the total number of available ports (size of the array) */ ++ int avail_total; ++ /** the number in use. */ ++ int inuse; ++}; ++ + /** + * Reuse TCP connection, still open can be used again. + */ +@@ -544,8 +582,6 @@ struct serviced_query { + * @param infra: pointer to infra cached used for serviced queries. + * @param rnd: stored to create random numbers for serviced queries. + * @param use_caps_for_id: enable to use 0x20 bits to encode id randomness. +- * @param availports: array of available ports. +- * @param numavailports: number of available ports in array. + * @param unwanted_threshold: when to take defensive action. + * @param unwanted_action: the action to take. + * @param unwanted_param: user parameter to action. +@@ -560,17 +596,18 @@ struct serviced_query { + * @param max_reuse_tcp_queries: max number of queries on a reuse connection. + * @param tcp_reuse_timeout: timeout for REUSE entries in milliseconds. + * @param tcp_auth_query_timeout: timeout in milliseconds for TCP queries to auth servers. ++ * @param shared_ports: the shared_ports structure. + * @return: the new structure (with no pending answers) or NULL on error. + */ + struct outside_network* outside_network_create(struct comm_base* base, + size_t bufsize, size_t num_ports, char** ifs, int num_ifs, + int do_ip4, int do_ip6, size_t num_tcp, int dscp, struct infra_cache* infra, +- struct ub_randstate* rnd, int use_caps_for_id, int* availports, +- int numavailports, size_t unwanted_threshold, int tcp_mss, ++ struct ub_randstate* rnd, int use_caps_for_id, ++ size_t unwanted_threshold, int tcp_mss, + void (*unwanted_action)(void*), void* unwanted_param, int do_udp, + void* sslctx, int delayclose, int tls_use_sni, struct dt_env *dtenv, + int udp_connect, int max_reuse_tcp_queries, int tcp_reuse_timeout, +- int tcp_auth_query_timeout); ++ int tcp_auth_query_timeout, struct shared_ports* shared_ports); + + /** + * Delete outside_network structure. +@@ -812,6 +849,54 @@ struct comm_point* outnet_comm_point_for_http(struct outside_network* outnet, + /** connect tcp connection to addr, 0 on failure */ + int outnet_tcp_connect(int s, struct sockaddr_storage* addr, socklen_t addrlen); + ++/** ++ * Create new shared ports structure. ++ * @param ifs: interface names (or NULL for default interface). ++ * These interfaces must be able to access all authoritative servers. ++ * @param num_ifs: number of names in array ifs. ++ * @param do_ip4: service IP4. ++ * @param do_ip6: service IP6. ++ * @param availports: array of available ports. ++ * @param numavailports: number of available ports in array. ++ * @return new, or NULL on failure. ++ */ ++struct shared_ports* shared_ports_create(char** ifs, int num_ifs, int do_ip4, ++ int do_ip6, int* availports, int numavailports); ++ ++/** ++ * Delete shared ports structure. ++ * @param shp: shared ports structure. ++ */ ++void shared_ports_delete(struct shared_ports* shp); ++ ++/** Find interface in shared ports. */ ++struct shared_ports_if* shared_ports_find_if(struct shared_ports* shp, ++ struct sockaddr_storage* addr, socklen_t addrlen, int pfxlen); ++ ++/** ++ * Get a shared port from the list of random ports. ++ * @param shp: shared ports structure. ++ * @param shpif: the shared ports interface. ++ * @param rnd: used to make random numbers. ++ * @param udp_connect: set to true if no reuse is possible. ++ * @param reusenum: number of ports that can be reused (already open). ++ * @param port: the port number is returned. ++ * @param reused: if the port numer is reused, returned. ++ * @return false on failure. That can mean no more free ports to use. ++ */ ++int shared_ports_fetch_random(struct shared_ports* shp, ++ struct shared_ports_if* shpif, struct ub_randstate* rnd, ++ int udp_connect, int reusenum, int* port, int* reused); ++ ++/** ++ * Return a shared port to the list of random ports. ++ * @param shp: shared ports structure. ++ * @param shpif: the shared ports interface. ++ * @param port: port number to return to be used again. ++ */ ++void shared_ports_return_port(struct shared_ports* shp, ++ struct shared_ports_if* shpif, int port); ++ + /** callback for incoming udp answers from the network */ + int outnet_udp_cb(struct comm_point* c, void* arg, int error, + struct comm_reply *reply_info); +diff --git a/testcode/fake_event.c b/testcode/fake_event.c +index ce439edd1..6b6ab3731 100644 +--- a/testcode/fake_event.c ++++ b/testcode/fake_event.c +@@ -1126,15 +1126,16 @@ outside_network_create(struct comm_base* base, size_t bufsize, + int ATTR_UNUSED(dscp), + struct infra_cache* infra, + struct ub_randstate* ATTR_UNUSED(rnd), +- int ATTR_UNUSED(use_caps_for_id), int* ATTR_UNUSED(availports), +- int ATTR_UNUSED(numavailports), size_t ATTR_UNUSED(unwanted_threshold), ++ int ATTR_UNUSED(use_caps_for_id), ++ size_t ATTR_UNUSED(unwanted_threshold), + int ATTR_UNUSED(outgoing_tcp_mss), + void (*unwanted_action)(void*), void* ATTR_UNUSED(unwanted_param), + int ATTR_UNUSED(do_udp), void* ATTR_UNUSED(sslctx), + int ATTR_UNUSED(delayclose), int ATTR_UNUSED(tls_use_sni), + struct dt_env* ATTR_UNUSED(dtenv), int ATTR_UNUSED(udp_connect), + int ATTR_UNUSED(max_reuse_tcp_queries), int ATTR_UNUSED(tcp_reuse_timeout), +- int ATTR_UNUSED(tcp_auth_query_timeout)) ++ int ATTR_UNUSED(tcp_auth_query_timeout), ++ struct shared_ports* ATTR_UNUSED(shared_ports)) + { + struct replay_runtime* runtime = (struct replay_runtime*)base; + struct outside_network* outnet = calloc(1, +@@ -1980,6 +1981,20 @@ int outnet_tcp_connect(int ATTR_UNUSED(s), struct sockaddr_storage* ATTR_UNUSED( + return 0; + } + ++struct shared_ports* shared_ports_create(char** ATTR_UNUSED(ifs), ++ int ATTR_UNUSED(num_ifs), int ATTR_UNUSED(do_ip4), ++ int ATTR_UNUSED(do_ip6), int* ATTR_UNUSED(availports), ++ int ATTR_UNUSED(numavailports)) ++{ ++ return calloc(1, sizeof(struct shared_ports)); ++} ++ ++void shared_ports_delete(struct shared_ports* shp) ++{ ++ if(!shp) return; ++ free(shp); ++} ++ + int tcp_req_info_add_meshstate(struct tcp_req_info* ATTR_UNUSED(req), + struct mesh_area* ATTR_UNUSED(mesh), struct mesh_state* ATTR_UNUSED(m)) + { +diff --git a/testcode/unittcpreuse.c b/testcode/unittcpreuse.c +index 5f45a4b45..ce62e3325 100644 +--- a/testcode/unittcpreuse.c ++++ b/testcode/unittcpreuse.c +@@ -41,6 +41,7 @@ + #include "config.h" + #include "testcode/unitmain.h" + #include "util/log.h" ++#include "util/net_help.h" + #include "util/random.h" + #include "services/outside_network.h" + +@@ -479,6 +480,278 @@ static void reuse_write_wait_test(void) + check_reuse_write_wait_removal(1, &reuse, store, 0, 1); + } + ++static void shared_port_test_ifs(void) ++{ ++ struct shared_ports* shp; ++ struct shared_ports_if* shpif; ++ char* ifs[] = {"1.2.3.4", "1.2.3.5", "::1:2", "::1:3"}; ++ int availports[] = {1, 2, 3, 4}; ++ struct sockaddr_storage addr; ++ socklen_t addrlen; ++ ++ shp = shared_ports_create(ifs, 4, 1, 1, availports, 4); ++ unit_assert(shp); ++ ++ if(!ipstrtoaddr("1.2.3.4", UNBOUND_DNS_PORT, &addr, &addrlen)) ++ log_err("could not parse"); ++ shpif = shared_ports_find_if(shp, &addr, addrlen, 0); ++ unit_assert(shpif); ++ ++ if(!ipstrtoaddr("1.2.3.5", UNBOUND_DNS_PORT, &addr, &addrlen)) ++ log_err("could not parse"); ++ shpif = shared_ports_find_if(shp, &addr, addrlen, 0); ++ unit_assert(shpif); ++ ++ if(!ipstrtoaddr("::1:2", UNBOUND_DNS_PORT, &addr, &addrlen)) ++ log_err("could not parse"); ++ shpif = shared_ports_find_if(shp, &addr, addrlen, 0); ++ unit_assert(shpif); ++ ++ if(!ipstrtoaddr("::1:3", UNBOUND_DNS_PORT, &addr, &addrlen)) ++ log_err("could not parse"); ++ shpif = shared_ports_find_if(shp, &addr, addrlen, 0); ++ unit_assert(shpif); ++ ++ shared_ports_delete(shp); ++} ++ ++/** See if a port is on the shared_ports ports list */ ++static int ++pif_list_contains(struct shared_ports_if* shpif, int item) ++{ ++ int i; ++ unit_assert(shpif->inuse >= 0 && shpif->inuse <= shpif->avail_total); ++ for(i=0; i< shpif->avail_total - shpif->inuse; i++) { ++ if(shpif->avail_ports[i] == item) ++ return 1; ++ } ++ return 0; ++} ++ ++/** See if a number of ports are on the shared_ports list */ ++static int ++pif_list_contains_items(struct shared_ports_if* shpif, int item1, ++ int item2, int item3, int item4) ++{ ++ if(item1 != -1 && !pif_list_contains(shpif, item1)) ++ return 0; ++ if(item2 != -1 && !pif_list_contains(shpif, item2)) ++ return 0; ++ if(item3 != -1 && !pif_list_contains(shpif, item3)) ++ return 0; ++ if(item4 != -1 && !pif_list_contains(shpif, item4)) ++ return 0; ++ return 1; ++} ++ ++static void shared_port_test_port(void) ++{ ++ struct shared_ports* shp; ++ struct shared_ports_if* shpif; ++ char* ifs[] = {"1.2.3.4", "1.2.3.5"}; ++ int availports[] = {1, 2, 3, 4}; ++ struct sockaddr_storage addr; ++ socklen_t addrlen; ++ int p1, p2, p3, reused; ++ struct ub_randstate* rnd; ++ ++ rnd = ub_initstate(NULL); ++ unit_assert(rnd); ++ ++ shp = shared_ports_create(ifs, 2, 1, 1, availports, 4); ++ unit_assert(shp); ++ ++ if(!ipstrtoaddr("1.2.3.4", UNBOUND_DNS_PORT, &addr, &addrlen)) ++ log_err("could not parse"); ++ shpif = shared_ports_find_if(shp, &addr, addrlen, 0); ++ unit_assert(shpif); ++ ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 0); ++ unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4)); ++ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p1 != 0); ++ unit_assert(!pif_list_contains(shpif, p1)); ++ if(p1 != 1) unit_assert(pif_list_contains(shpif, 1)); ++ if(p1 != 2) unit_assert(pif_list_contains(shpif, 2)); ++ if(p1 != 3) unit_assert(pif_list_contains(shpif, 3)); ++ if(p1 != 4) unit_assert(pif_list_contains(shpif, 4)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 1); ++ ++ shared_ports_return_port(shp, shpif, p1); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 0); ++ unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4)); ++ ++ /* pick up two items */ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p1 != 0); ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p2, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p2 != 0); ++ unit_assert(!pif_list_contains(shpif, p1)); ++ unit_assert(!pif_list_contains(shpif, p2)); ++ if(p1 != 1 && p2 != 1) unit_assert(pif_list_contains(shpif, 1)); ++ if(p1 != 2 && p2 != 2) unit_assert(pif_list_contains(shpif, 2)); ++ if(p1 != 3 && p2 != 3) unit_assert(pif_list_contains(shpif, 3)); ++ if(p1 != 4 && p2 != 4) unit_assert(pif_list_contains(shpif, 4)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 2); ++ ++ shared_ports_return_port(shp, shpif, p1); ++ unit_assert(pif_list_contains(shpif, p1)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 1); ++ ++ shared_ports_return_port(shp, shpif, p2); ++ unit_assert(pif_list_contains(shpif, p2)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 0); ++ unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4)); ++ ++ /* pick up three items */ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p1 != 0); ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p2, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p2 != 0); ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p3, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p3 != 0); ++ unit_assert(!pif_list_contains(shpif, p1)); ++ unit_assert(!pif_list_contains(shpif, p2)); ++ unit_assert(!pif_list_contains(shpif, p3)); ++ if(p1 != 1 && p2 != 1 && p3 != 1) ++ unit_assert(pif_list_contains(shpif, 1)); ++ if(p1 != 2 && p2 != 2 && p3 != 2) ++ unit_assert(pif_list_contains(shpif, 2)); ++ if(p1 != 3 && p2 != 3 && p3 != 3) ++ unit_assert(pif_list_contains(shpif, 3)); ++ if(p1 != 4 && p2 != 4 && p3 != 4) ++ unit_assert(pif_list_contains(shpif, 4)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 3); ++ ++ shared_ports_return_port(shp, shpif, p1); ++ unit_assert(pif_list_contains(shpif, p1)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 2); ++ ++ shared_ports_return_port(shp, shpif, p2); ++ unit_assert(pif_list_contains(shpif, p2)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 1); ++ ++ shared_ports_return_port(shp, shpif, p3); ++ unit_assert(pif_list_contains(shpif, p3)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 0); ++ unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4)); ++ ++ /* pick up all four items */ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p1 != 0); ++ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p1 != 0); ++ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p1 != 0); ++ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0, 0, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 0); ++ unit_assert(p1 != 0); ++ unit_assert(!pif_list_contains(shpif, 1)); ++ unit_assert(!pif_list_contains(shpif, 2)); ++ unit_assert(!pif_list_contains(shpif, 3)); ++ unit_assert(!pif_list_contains(shpif, 4)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 4); ++ ++ /* more fetches fail, it is fully inuse. */ ++ unit_assert(!shared_ports_fetch_random(shp, shpif, rnd, 0, 0, &p2, ++ &reused)); ++ unit_assert(!shared_ports_fetch_random(shp, shpif, rnd, 0, 0, &p3, ++ &reused)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 4); ++ ++ /* reuse is then always the case */ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0 /* can reuse */, 4 /* reusenum */, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 1); ++ unit_assert(p1 >= 0 && p1 < 4 /* reusenum */); ++ ++ if(!shared_ports_fetch_random(shp, shpif, rnd, ++ 0 /* can reuse */, 4 /* reusenum */, &p1, &reused)) { ++ unit_assert(0); /* should succeed */ ++ } ++ unit_assert(reused == 1); ++ unit_assert(p1 >= 0 && p1 < 4 /* reusenum */); ++ ++ /* return all the ports */ ++ shared_ports_return_port(shp, shpif, 1); ++ unit_assert(pif_list_contains(shpif, 1)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 3); ++ shared_ports_return_port(shp, shpif, 2); ++ unit_assert(pif_list_contains(shpif, 2)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 2); ++ shared_ports_return_port(shp, shpif, 3); ++ unit_assert(pif_list_contains(shpif, 3)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 1); ++ shared_ports_return_port(shp, shpif, 4); ++ unit_assert(pif_list_contains(shpif, 4)); ++ unit_assert(shpif->avail_total == 4); ++ unit_assert(shpif->inuse == 0); ++ unit_assert(pif_list_contains_items(shpif, 1, 2, 3, 4)); ++ ++ shared_ports_delete(shp); ++ ub_randfree(rnd); ++} ++ + void tcpreuse_test(void) + { + unit_show_feature("tcp_reuse"); +@@ -486,4 +759,7 @@ void tcpreuse_test(void) + tcp_reuse_tree_list_test(); + waiting_tcp_list_test(); + reuse_write_wait_test(); ++ unit_show_feature("shared_ports"); ++ shared_port_test_ifs(); ++ shared_port_test_port(); + } diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 0a511f767e..76dc0655c9 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -33,6 +33,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-50243.patch \ file://CVE-2026-50248.patch \ file://CVE-2026-50251.patch \ + file://CVE-2026-50252.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97917 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id CB03BC88E46 for ; Thu, 10 Sep 2026 23:10:57 +0000 (UTC) Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27857.1789081850812243264 for ; Thu, 10 Sep 2026 16:10:50 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=nJXUBgPw; spf=pass (domain: gmail.com, ip: 209.85.214.180, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2dcff8f44f2so3632465ad.1 for ; Thu, 10 Sep 2026 16:10:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081850; x=1789686650; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fP0b60bAffhb9ain1P8kIfg8WLZNvp4bZxfJAAwCOnw=; b=nJXUBgPwxo+2jYwv1WQhph0xzX8qYFCIn6DMLj0HehdnqgP4CZDG8RjYrB2H64NXNQ 8VjUrNtsSnE6SZi0hK5HvdoBLHiayx1zrCulGs+xKV8NNUsJx6Ylr7Uk5vgE/jfqksK/ +Y83VtceTCGset9s3tMLUz91+6FwFdmosH6C8Ykx2VAkncfpuPueokbqtoDiFXjDBUSN 8PLIKqyiD31IP8T03sac7tvfHPQZtsbIfd6YI3a3/YY4wTPgS8OyDpvuzRVYU6kHLB7e +9tM0LFs2Zi21LH8KZ1mNNfRO3QwItrhHTz6GtCmXYQCqsH9CW4F36t76N9uGSJQg8DP fYww== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081850; x=1789686650; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=fP0b60bAffhb9ain1P8kIfg8WLZNvp4bZxfJAAwCOnw=; b=IWgasAhDRkl3TjP6qFh0zZvNngX+Kb5Q+92HUlsliyBFHfwFnG4ePwdG24e3I1FREC jYsPuZIjxtGKYwWXA5zz4Soqlax95ZmmHIPtwNP0nllfU/qZy7pz2VsneYEjwLNv99a0 j26mW1AsVDFXNty8uMu+grlR6VCdWJUEaWYcRFxcrDZO12aQlxMtonnmd5/He5uC3p2l UXpoXc5sFHFpFP6Dk+ITQWZd12AHaDHHXjDYSh4aKAFoCwzpbgje6FeURclJ7X5NaF0W aYsEqhutjjKHMWrWbUFX/n/H3/B5gpy0/lbjJiLhKDxBkSYCYvZ7qF6UP/sL4WsGciym tW+g== X-Gm-Message-State: AFuF++m9P690Ze9paoy8g2sUkafYO/nMWqI6pKGZQ32EUNW95+dyhTWf xQFcNvayxuIbu7yjbNpjCQlGu1KUWkCEclGk++LYPB9jGV0A6Qh29InAL/Il5w== X-Gm-Gg: AYBFou2f0k8LHpoioWKGAvj7hVW0PDmxmOyWWcuYK2QTfObsEaCWCVkayiQl8zYiwQ9 KJB4QG7evj6UAcIjHC+FNzCCSlDFQLhvVsyQf35gVfDppPs/eYkjmjzrePy5lc013WSXM3hGPbm cxEGWwh61VMC58JKcskfJPy8Ug8Mesc2alIs/lVEy2iH+xmx3yZW5TQqpvJ/p1ZvvNIeUCpgs28 K25gzHyzZqcmlUfkzUZ62xUa5mL94RAKcf45COjmbAkESD0s2G5WAPCXROhZ0RRTamqolQM85cu POnda/aJ37O3ceEjdcPQlHMh+UTwr66DIAD2ToyVtQwj/Z8420Q7pRf3xVrm/WvI28+1yiEyI2g mItBw37IPmpW7D9smBFfw1ZQfm/tjVAk+t9mCkjVshbK9K5bQ5vKNjTUaYxU0A3Qz1UMeARlYA6 8t4iGBcOYJwnjLyEM89oWz+7lZz0PM1nxKhdgbGwpWU/fXnIjmPlwcXAUlApNVWFCCFKLxu7/rF NDDLs0HRk1Fap+Ts64IZDo= X-Received: by 2002:a17:90a:da8f:b0:396:6344:3b63 with SMTP id 98e67ed59e1d1-39d9bbee490mr1624043a91.2.1789081850107; Thu, 10 Sep 2026 16:10:50 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:49 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 24/32] unbound: patch CVE-2026-52863 Date: Fri, 11 Sep 2026 11:09:23 +1200 Message-ID: <20260910230932.173913-24-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129942 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-52863 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-52863.patch | 132 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 133 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-52863.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-52863.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-52863.patch new file mode 100644 index 0000000000..5523faa2f6 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-52863.patch @@ -0,0 +1,132 @@ +From da55f7d129bfa01201d8e2bb58b13674f41c572e Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:16:03 +0200 +Subject: [PATCH] - Fix CVE-2026-52863, Memory corruption could lead to crash + and denial of service. Thanks to Qifan Zhang, Palo Alto Networks, for the + report. + +(cherry picked from commit 8c702de175cb687d9645603ad3e8dc7c08a925e8) + +CVE: CVE-2026-52863 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/8c702de175cb687d9645603ad3e8dc7c08a925e8] + +Signed-off-by: Ankur Tyagi +--- + services/mesh.c | 8 +++++-- + services/mesh.h | 4 ++++ + testcode/unitmain.c | 56 +++++++++++++++++++++++++++++++++++++++++++++ + 3 files changed, 66 insertions(+), 2 deletions(-) + +diff --git a/services/mesh.c b/services/mesh.c +index 23499dcef..6a04bc838 100644 +--- a/services/mesh.c ++++ b/services/mesh.c +@@ -911,8 +911,7 @@ cfg_region_strlist_copy(struct regional* region, struct config_strlist* list) + return result; + } + +-/** Copy the client info to the query region. */ +-static struct respip_client_info* ++struct respip_client_info* + mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo) + { + size_t i; +@@ -957,6 +956,11 @@ mesh_copy_client_info(struct regional* region, struct respip_client_info* cinfo) + cinfo->view->name); + if(!client_info->view_name) + return NULL; ++ } else if(cinfo->view_name) { ++ client_info->view_name = regional_strdup(region, ++ cinfo->view_name); ++ if(!client_info->view_name) ++ return NULL; + } + return client_info; + } +diff --git a/services/mesh.h b/services/mesh.h +index a61f90993..b3e1f0efa 100644 +--- a/services/mesh.h ++++ b/services/mesh.h +@@ -729,4 +729,8 @@ void mesh_respond_serve_expired(struct mesh_state* mstate); + void mesh_remove_callback(struct mesh_area* mesh, struct query_info* qinfo, + uint16_t qflags, mesh_cb_func_type cb, void* cb_arg); + ++/** Copy the client info to the query region. */ ++struct respip_client_info* mesh_copy_client_info(struct regional* region, ++ struct respip_client_info* cinfo); ++ + #endif /* SERVICES_MESH_H */ +diff --git a/testcode/unitmain.c b/testcode/unitmain.c +index beb10ba45..edde04875 100644 +--- a/testcode/unitmain.c ++++ b/testcode/unitmain.c +@@ -1282,6 +1282,61 @@ static void localzone_test(void) + localzone_parents_test(); + } + ++#include "services/mesh.h" ++/** mesh unit tests */ ++static void mesh_test(void) ++{ ++ struct regional* r2, *r3; ++ struct respip_client_info* c1, *c2, *c3; ++ unit_show_func("services/mesh.c", "mesh_copy_client_info"); ++ r2 = regional_create(); ++ r3 = regional_create(); ++ if(!r2 || !r3) fatal_exit("out of memory"); ++ ++ c1 = calloc(1, sizeof(*c1)); ++ if(!c1) fatal_exit("out of memory"); ++ c1->view = calloc(1, sizeof(*c1->view)); ++ if(!c1->view) fatal_exit("out of memory"); ++ c1->view->name = strdup("view1"); ++ if(!c1->view->name) fatal_exit("out of memory"); ++ ++ c2 = mesh_copy_client_info(r2, c1); ++ if(!c2) fatal_exit("out of memory"); ++ c3 = mesh_copy_client_info(r3, c2); ++ if(!c3) fatal_exit("out of memory"); ++ ++ unit_assert(strcmp(c1->view->name, c2->view_name) == 0); ++ unit_assert(strcmp(c1->view->name, c3->view_name) == 0); ++ ++ /* make sure that the c3 view_name is in the r3 region. */ ++ unit_assert(r3->next == NULL); /* only the first chunk present atm */ ++ if(strlen(c3->view_name) >= r3->large_object_size) { ++ char* a = r3->large_list; ++ int found = 0; ++ while(a) { ++ if(strcmp(c3->view_name, ++ a + /* ALIGNEMENT */ sizeof(uint64_t)) == 0) { ++ found = 1; ++ break; ++ } ++ a = *(char**)a; ++ } ++ unit_assert(found == 1); ++ } else { ++ /* The allocation is expected in the r3 region first chunk */ ++ unit_assert((uint8_t*)c3->view_name < ((uint8_t*)r3)+r3->first_size); ++ } ++ ++ regional_destroy(r2); ++ /* ASAN should complain for the freed access below */ ++ unit_assert(strcmp(c1->view->name, c3->view_name) == 0); ++ ++ regional_destroy(r3); ++ free(c1->view->name); ++ free(c1->view); ++ free(c1); ++} ++ + void unit_show_func(const char* file, const char* func) + { + printf("test %s:%s\n", file, func); +@@ -1356,6 +1411,7 @@ main(int argc, char* argv[]) + msgparse_test(); + edns_ede_answer_encode_test(); + localzone_test(); ++ mesh_test(); + #ifdef CLIENT_SUBNET + ecs_test(); + #endif /* CLIENT_SUBNET */ diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 76dc0655c9..a03dcf4193 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -34,6 +34,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-50248.patch \ file://CVE-2026-50251.patch \ file://CVE-2026-50252.patch \ + file://CVE-2026-52863.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:24 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97915 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id DD278C88E45 for ; Thu, 10 Sep 2026 23:10:57 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27785.1789081853787502642 for ; Thu, 10 Sep 2026 16:10:53 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=LnMmxTYV; spf=pass (domain: gmail.com, ip: 74.125.227.140, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj2-f12.google.com with SMTP id d9443c01a7336-2d90ba1d807so2692135ad.3 for ; Thu, 10 Sep 2026 16:10:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081853; x=1789686653; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hmf6kn/dh/xIaEcQJ9E3foESLqAmsxuGTMN6jm2PH3w=; b=LnMmxTYV+OUbGeO7b/Nu4mYLSqSE3FMB6jXuyJWhpGRJDVSjddb6rpHObdIGi9NwFU U/zohbKKPy08YwDO2Q7hROV5p4HsIlJoVD5ulTdnyzXu9q0F11r+ZwTINyj0FVstgaW5 y+4VbwUCTiVsoHk0sWslLzks8TScB9l/VTXjppGQUUtTbb/PW81tWo7iErz1XfXdmtAd 1VEQT7te2PmXrHEhsk08apx0a9Idp5HWK6lsRUPYNKxXjNdPd8bZ2DOfEc381I5JsJly NHk2u/LrE5caGwlp1ipt2NP9CYXYJe2kH9PMrX3dl4oI7VJsJ5Hmmx1vFIl4zndu2Wx0 cWLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081853; x=1789686653; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hmf6kn/dh/xIaEcQJ9E3foESLqAmsxuGTMN6jm2PH3w=; b=Yk/vtfLVIoPfu9IpTgAY7vVRooJZ6InAZRV5bBmD169j0BHmbrfiuvOpBMl4GiCEAj owEpl8Z5FQLON5dFYOpyZz0JQWum7RDnfBbvIGzX18D1bOEToFy9p+BS4pGfCZPK51xo ksbWzVC+aa1gKlYJiM03dOIyKIE12nGGLGeNWmiDJlvd1Dvpnw9FaL/tAgsll+1/UTZv /NJWR0YoDAt2Qt0rGYGtqJk4/PzkLLxpR9+BdZ9ceHB458yhwIVhi1pOHH6XsnKO5bqM +n4h9f5eAceFeRYB8VYUbyEDVbz9RMO3grGR/T+CFiMkP/sRkmqCczn5a9W2iyC4ggLZ kZzA== X-Gm-Message-State: AFuF++lIlvve1yPCkLmBxqAxcWjqpsnMlJ6nrH6lAoPtPyb6FT2kdjBF 38rzqyXOtg/I9Ap+hgYu0LA2F/nhGpgMnqNeeHjEXu2IDP2YdWWETa9xlZuVYQ== X-Gm-Gg: AYBFou05qlRaeUa9k9Pl3gLY6yAJT107HuBVSpxeDI+4dtuMFDSXraFB0D27l+7yPNg zf+qQlDZX1OfQqqYwV1DwMOVXZ+CJhAoZTYNZdb5n+2XOTXq3mQhQvvZ1f9wcuTDnfJwLd0Z0ya OexYMGuS5FZFiW8kQDgR/0Ag3Dbl+wT+9SVCFPZk5snpL5d4mbd5MfcLqbUWzQm1mbitlD0uWdC xTKvX5VFvDKJ06c39LFdAewaDfXwK6ode30jeWEybF83zT/0ox3LPBd8WXY7Li6rzmGkryyJmx2 7v0JFkXyx7HVlb41ElSBXdkMU33iha+CLWFSTdQ9ZR+G+6OCP6Euok5WoLV2h4LObU83dR5N7QQ /hG0UpXLOv0sk69uiBG+td8tYeYkcSiGFCcYJTi0r4YYJne83JJkUBrJnoZNe1QBPVHrNZ58lg4 yOy/SHnsy+ahNUiVcIMjDkwd68d0nOGZE1n4NqThBFm2amh9J5Few3cpG3JYd74UvhPTa5f6VVm J93Nx8Sl88pKd3bxIXWZnqtbg== X-Received: by 2002:a17:90b:5246:b0:398:d2a0:87ff with SMTP id 98e67ed59e1d1-39d9bc67660mr1895524a91.1.1789081853138; Thu, 10 Sep 2026 16:10:53 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:52 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 25/32] unbound: patch CVE-2026-54478 Date: Fri, 11 Sep 2026 11:09:24 +1200 Message-ID: <20260910230932.173913-25-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129943 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-54478 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-54478.patch | 38 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 39 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-54478.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-54478.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-54478.patch new file mode 100644 index 0000000000..3580815477 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-54478.patch @@ -0,0 +1,38 @@ +From 44af1c8b392afb7d14ae0814fb9c6c037a5bf18a Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:16:42 +0200 +Subject: [PATCH] - Fix CVE-2026-54478, DNS Cookie bypass when combined with + proxy-protocol use. Thanks to Qifan Zhang, Palo Alto Networks, for the + report. + +(cherry picked from commit 8a15ffee620bce05fbfd2c69b0d4c31c10a02431) + +CVE: CVE-2026-54478 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/8a15ffee620bce05fbfd2c69b0d4c31c10a02431] + +Signed-off-by: Ankur Tyagi +--- + util/data/msgparse.c | 6 +++--- + 1 file changed, 3 insertions(+), 3 deletions(-) + +diff --git a/util/data/msgparse.c b/util/data/msgparse.c +index 169709b7e..3dc2e1264 100644 +--- a/util/data/msgparse.c ++++ b/util/data/msgparse.c +@@ -1068,13 +1068,13 @@ parse_edns_options_from_query(uint8_t* rdata_ptr, size_t rdata_len, + * purposes. It will be overwritten if (re)creation + * is needed. + */ +- if(repinfo->remote_addr.ss_family == AF_INET) { ++ if(repinfo->client_addr.ss_family == AF_INET) { + memcpy(server_cookie + 16, +- &((struct sockaddr_in*)&repinfo->remote_addr)->sin_addr, 4); ++ &((struct sockaddr_in*)&repinfo->client_addr)->sin_addr, 4); + } else { + cookie_is_v4 = 0; + memcpy(server_cookie + 16, +- &((struct sockaddr_in6*)&repinfo->remote_addr)->sin6_addr, 16); ++ &((struct sockaddr_in6*)&repinfo->client_addr)->sin6_addr, 16); + } + + if(cfg->cookie_secret_file && diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index a03dcf4193..1e3bd6f5c6 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -35,6 +35,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-50251.patch \ file://CVE-2026-50252.patch \ file://CVE-2026-52863.patch \ + file://CVE-2026-54478.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:25 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97914 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id B5F59C88E41 for ; Thu, 10 Sep 2026 23:10:57 +0000 (UTC) Received: from mail-pj2-f12.google.com (mail-pj2-f12.google.com [74.125.227.140]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27787.1789081856453926778 for ; Thu, 10 Sep 2026 16:10:56 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Q4cQcSOX; spf=pass (domain: gmail.com, ip: 74.125.227.140, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj2-f12.google.com with SMTP id 98e67ed59e1d1-398beb616f5so90545a91.1 for ; Thu, 10 Sep 2026 16:10:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081856; x=1789686656; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=idPz84pCpMSmNlxNc1cH6FmUspn+JaYACcTJokSIXf0=; b=Q4cQcSOXjr7STlhm8xb/5K6+JIJa7K6HSDb8rOves1M0LIelAQhWMRG+VMxVTPE5No B20GWcj9AnaxMdG6vjXIfPzsPzroY9OL52SKdq0VQNZF29wauQlasVQM3jS06K1y96oC vgDNJ1aCYdFMoyND0nIhHVIdbBA6JB6NQi13mJi1nmOdmeuy5wc1zRVUnoJotDWPOm/i DKnOjMC46sMC/I03a1Ffh5+s4pn34pOaPQAyeSDD7XiqcHpaHhsfd0WJD0uKiEEDcRUO wquuI71FDHmL9gHMic9TLvH1vNf3kii3mqcc4Nz5RBhHMt2+fS8gHQ0bjrsYdwGGG01Z NUXA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081856; x=1789686656; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=idPz84pCpMSmNlxNc1cH6FmUspn+JaYACcTJokSIXf0=; b=odKp+cL0V9mOpUC93px8HKOTvEq8dvJP2M0Ua8SEqR4brHs9kNxI9AgkMYGZqWqn23 uBuADY8Ux/o2cnKF5/JPzE/FxJb8MIsOSujS4YJ9Pv1C7P8EG80M9naggbqbOzOugXia Oz46euiVl21EOki9XkMqm1q/QNxI8uW7At1mQUtflSMlUferpITqeypSK0/lvBIUB2IG a2Js1teChH+BRFD8qwc3sjNR1j5k/SoCRwMuWeDxsjbtC7Nb4/tzgEQx3BEKKkwwRGbW /99dEJkwv64o+BgjE4HJmGd/2agL54S82z6kVeiKKT2StgvVTp/mrJvNDdlLyBazUSMV /pWw== X-Gm-Message-State: AFuF++l/am+A+0DMnHkjCPk52QnUMEA9X5YIP1Ggq6Y7ornwrB6UkKdr qQyCp1NAQuz4d/VtrGbdTdvnWkrIwnonRVFcNU6aWasOXBtgGoKb4mfB5H5Y2g== X-Gm-Gg: AYBFou1+3nca3XG13a7h73irbTZLDe0YDR6YXcMVnkhuEruDU+jWSxP42iJOXZDGJEP WqRffVF6OBM9czTyrhZQqqxOaHebzeQZ3ca3DblPbJ3vlMkWZ4FeZ5eunYkVtEAmQgK1NBOjPfG Fbt1J9zeqpe5/O4t+TVPAwex9KU3crxI/i0/byjK9iqO0b6ESseAno1pix5QS+lVWO9vdYOrk4e 1duUqiaR2TuPKplfllXzDFQKhHr9fypooRdXVFSLw7vfiAMADllIjWM/VEFKXDrVtqbAKDW44nL fEzYYsN7hTMFPIJFNqfA/60gpgpwOoxaJme/U4rMblqOxkzFF4gK42c9PKK/XrObtzFaK/PgJrw iTrsFN4HfducC7iTUCVt0DwMpopIuk/uSyek4CADXVlpKNLVJIs/nZL94D/xc3qWNsOIEZnsJBI n2tXH0nnkxTjFoFSKlcdII1onDSbMOy5jE1vT4SkSpeocG6uYx0dOV9Mi7hjVwoqdvJuRt22iLl iPUVIycnLJS8vdMddnEBls= X-Received: by 2002:a17:90b:5108:b0:38f:657:6823 with SMTP id 98e67ed59e1d1-39d97f392d3mr1589477a91.8.1789081855775; Thu, 10 Sep 2026 16:10:55 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:55 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 26/32] unbound: patch CVE-2026-55708 Date: Fri, 11 Sep 2026 11:09:25 +1200 Message-ID: <20260910230932.173913-26-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:10:57 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129944 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-55708 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-55708.patch | 51 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-55708.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-55708.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55708.patch new file mode 100644 index 0000000000..402e38c737 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55708.patch @@ -0,0 +1,51 @@ +From 1138101d9147db0539c27e9c19525223f32de84c Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:17:10 +0200 +Subject: [PATCH] - Fix CVE-2026-55708, Privacy/configuration issue when adding + local data in views through 'unbound-control'. Thanks to Qifan Zhang, + Palo Alto Networks, for the report. + +(cherry picked from commit c29ff70f6aa9bb2f02e5f21001832f2b4791bd76) + +CVE: CVE-2026-55708 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/c29ff70f6aa9bb2f02e5f21001832f2b4791bd76] + +Signed-off-by: Ankur Tyagi +--- + daemon/remote.c | 16 ++++++++++++++++ + 1 file changed, 16 insertions(+) + +diff --git a/daemon/remote.c b/daemon/remote.c +index d8ee7fa7d..8a26dadc7 100644 +--- a/daemon/remote.c ++++ b/daemon/remote.c +@@ -1634,6 +1634,14 @@ do_view_data_add(RES* ssl, struct worker* worker, char* arg) + ssl_printf(ssl,"error out of memory\n"); + return; + } ++ if(!v->isfirst) { ++ /* Global local-zone is not used for this view, ++ * therefore add defaults to this view-specific ++ * local-zone. */ ++ struct config_file lz_cfg; ++ memset(&lz_cfg, 0, sizeof(lz_cfg)); ++ local_zone_enter_defaults(v->local_zones, &lz_cfg); ++ } + } + do_data_add(ssl, v->local_zones, arg2); + lock_rw_unlock(&v->lock); +@@ -1659,6 +1667,14 @@ do_view_datas_add(struct daemon_remote* rc, RES* ssl, struct worker* worker, + ssl_printf(ssl,"error out of memory\n"); + return; + } ++ if(!v->isfirst) { ++ /* Global local-zone is not used for this view, ++ * therefore add defaults to this view-specific ++ * local-zone. */ ++ struct config_file lz_cfg; ++ memset(&lz_cfg, 0, sizeof(lz_cfg)); ++ local_zone_enter_defaults(v->local_zones, &lz_cfg); ++ } + } + /* put the view name in the command buf */ + (void)snprintf(buf+strlen(buf), sizeof(buf)-strlen(buf), "%s ", arg); diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 1e3bd6f5c6..a04080c751 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -36,6 +36,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-50252.patch \ file://CVE-2026-52863.patch \ file://CVE-2026-54478.patch \ + file://CVE-2026-55708.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:26 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97919 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E4BD8C88E41 for ; Thu, 10 Sep 2026 23:11:07 +0000 (UTC) Received: from mail-pj1-f42.google.com (mail-pj1-f42.google.com [209.85.216.42]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27860.1789081859310553655 for ; Thu, 10 Sep 2026 16:10:59 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=XGnHM+GH; spf=pass (domain: gmail.com, ip: 209.85.216.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f42.google.com with SMTP id 98e67ed59e1d1-398e9698a70so339210a91.0 for ; Thu, 10 Sep 2026 16:10:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081859; x=1789686659; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vfKIElfFsZhBLTrJZ6w2QI4ahE39JaOWrIBVGSHA7A4=; b=XGnHM+GHozonvVvrbUcoDMMTMd+eaC2hwX0Yb08/0Q/SQjAztAgiPwyzencD9APg6l TvbfEKCuF1wBFZhh0WU0tSY0BncTEEPUYRDKz6V4r5BQ6A8vl60V1m1u3wikBECvky4H S1m7pd4JVB49Inbu12c3ADheMKf+dLbouOOKscfwKDe/bBs81ZREnFkCRucxMJDZJKRp sAVIakxuV83Wwhcn63YY8C3/KE9bTgGw2brwg2MZdA/5zqLREoOusjYm7yjDnW6Z1C0D mY1w3+qqUEzbRDJ2x/QBppKpnTyOk/8msc4sXHZU5UI0nNOqQuxStifDJ3eJhUFWq39H OdwQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081859; x=1789686659; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=vfKIElfFsZhBLTrJZ6w2QI4ahE39JaOWrIBVGSHA7A4=; b=D4JYowcA4kqTuB1ER+Cray0INfaxr9xqyaZy1xBLJZHMoDdVaa/dprhRY+A5a5EPz4 Ie5lOUMW570atktIbuUINvRVyakOZUHw8w5LxQpYD0EZq7zdXbNmPU7BLgXhV8n0mGLj H2jeAIgUQlQccL367jYxr2ge0ZGmSzXtw72SJRwHMGshORhz+O7dMNPMJQIcgdlArFJR 7J4VcqwPyuRNCK5eKYwxaVUlp+JeUbXt5kD4GTIK7XMfau8cwDchMXevGIwygJSr5Z8w 2Y2cviWAinqsFTX9+oV/DpI/VLUy+YpQgmx0ZZmoSLSOtXraI6zDb34+WBWC3vUbwfKs fXGA== X-Gm-Message-State: AFuF++lv0JbEwhGStaO9PiC5+V3L2chjHg/cmF3EEu3noctKjyOGoLAK kgybBTiDVOsZieJFkI+N2dYsezGN6iHeoTf8/asWoCC6FPZRsS8O36IUqNWu/Q== X-Gm-Gg: AYBFou0M1BOwQzLui5apegwUyaKEnFlCLjYy6NHl+7PMlCaEmkI8ZykVujL0hmXv2bB iWqUndDdO+ciBjIqJ6ZrTvjpf6WRXs4zMHaURq4tFfqjKfCqprDLhZlOiZash9pgUny28Xr3v5q XOT/vEcSy9GmB2Tte/8QVM48r9td2D+luyRPUtXnYccacct4zlb1U+S8t0kJK2Jx66WLsD8N0ey AnvgKPJ/XEkjDiyxP66YiZ5Q5mEFwcV6POYYAFjDTlHfZIRBS74hKUW/R1VhpwBFDaMSNyevLlt oOViPoRNCTfoZxWMICUf+8hUD0qQBWKQeXLDU35lJRof9sJuErAhq2xyHSYd+miEKtPVcDId8fb UvFxYQE3M6s5cPuJPCO1XNCSl1jBMGyiZ61zrykvaPNP2VTbMhTVHNNcoqghOfM3D+hd5G83odD Y63geQcn57BD1+1/xRgEitRFlDGvU7gz40zgzuCj0pp1uQS7/zmb+GqMffLyojVzREjnMbf5OJA QtvP3ks8sbN6ok6+xYEFI1wJnQcXhlLLQ== X-Received: by 2002:a17:90a:d64c:b0:392:6638:2e6a with SMTP id 98e67ed59e1d1-39d9c1d260amr1591719a91.13.1789081858508; Thu, 10 Sep 2026 16:10:58 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:10:58 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 27/32] unbound: patch CVE-2026-55717 Date: Fri, 11 Sep 2026 11:09:26 +1200 Message-ID: <20260910230932.173913-27-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:11:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129945 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-55717 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-55717.patch | 90 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 91 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-55717.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-55717.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55717.patch new file mode 100644 index 0000000000..fcb223029d --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55717.patch @@ -0,0 +1,90 @@ +From ff034061b24642e15340b0696e5c9a0aa8410fab Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:17:32 +0200 +Subject: [PATCH] - Fix CVE-2026-55717, 'serve-expired-client-timeout' and + 'response-ip' CNAME redirect could lead to a crash. Thanks to Qifan Zhang, + Palo Alto Networks, for the report. In addition, thanks to Xin Wang, + Jiapeng Li, and Jiajia Liu, Northwestern Polytechnical University, for also + reporting this issue. + +(cherry picked from commit 2ce2ca36912644d2dbf97249a41494a9e2500fc3) + +CVE: CVE-2026-55717 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/2ce2ca36912644d2dbf97249a41494a9e2500fc3] + +Signed-off-by: Ankur Tyagi +--- + services/localzone.h | 2 +- + services/mesh.c | 15 ++++++++++----- + util/data/packed_rrset.c | 1 + + 3 files changed, 12 insertions(+), 6 deletions(-) + +diff --git a/services/localzone.h b/services/localzone.h +index 66102fd98..9ec57e2a1 100644 +--- a/services/localzone.h ++++ b/services/localzone.h +@@ -565,7 +565,7 @@ enum respip_action { + respip_always_nxdomain = local_zone_always_nxdomain, + /** answer with nodata response */ + respip_always_nodata = local_zone_always_nodata, +- /** answer with nodata response */ ++ /** drop query */ + respip_always_deny = local_zone_always_deny, + /** RPZ: truncate answer in order to force switch to tcp */ + respip_truncate = local_zone_truncate, +diff --git a/services/mesh.c b/services/mesh.c +index 6a04bc838..191b1d488 100644 +--- a/services/mesh.c ++++ b/services/mesh.c +@@ -2391,9 +2391,10 @@ apply_respip_action(struct module_qstate* qstate, + + /* xxx_deny actions mean dropping the reply, unless the original reply + * was redirected to response-ip data. */ +- if((actinfo->action == respip_deny || ++ if(actinfo->action == respip_always_deny || ++ ((actinfo->action == respip_deny || + actinfo->action == respip_inform_deny) && +- *encode_repp == rep) ++ *encode_repp == rep)) + *encode_repp = NULL; + + return 1; +@@ -2458,12 +2459,15 @@ mesh_serve_expired_callback(void* arg) + qstate->client_info, &actinfo, msg->rep, &alias_rrset, &encode_rep, + qstate->env->auth_zones)) { + return; +- } else if(partial_rep && +- !respip_merge_cname(partial_rep, &qstate->qinfo, msg->rep, ++ } else if(partial_rep) { ++ if(!respip_merge_cname(partial_rep, &qstate->qinfo, msg->rep, + qstate->client_info, must_validate, &encode_rep, qstate->region, + qstate->env->auth_zones, qstate->env->views, + qstate->env->respip_set)) { +- return; ++ return; ++ } ++ /* merge succeeded; final reply, no further alias pass */ ++ partial_rep = NULL; + } + if(!encode_rep || alias_rrset) { + if(!encode_rep) { +@@ -2474,6 +2478,7 @@ mesh_serve_expired_callback(void* arg) + partial_rep = encode_rep; + } + } ++ msg->rep = encode_rep; + /* We've found a partial reply ending with an + * alias. Replace the lookup qinfo for the + * alias target and lookup the cache again to +diff --git a/util/data/packed_rrset.c b/util/data/packed_rrset.c +index d18486cc5..720c56ac3 100644 +--- a/util/data/packed_rrset.c ++++ b/util/data/packed_rrset.c +@@ -198,6 +198,7 @@ get_cname_target(struct ub_packed_rrset_key* rrset, uint8_t** dname, + { + struct packed_rrset_data* d; + size_t len; ++ if(!rrset) return; + if(ntohs(rrset->rk.type) != LDNS_RR_TYPE_CNAME && + ntohs(rrset->rk.type) != LDNS_RR_TYPE_DNAME) + return; diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index a04080c751..0af51973cd 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -37,6 +37,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-52863.patch \ file://CVE-2026-54478.patch \ file://CVE-2026-55708.patch \ + file://CVE-2026-55717.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:27 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97921 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 07A61C88E46 for ; Thu, 10 Sep 2026 23:11:08 +0000 (UTC) Received: from mail-pj1-f49.google.com (mail-pj1-f49.google.com [209.85.216.49]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27864.1789081861804094755 for ; Thu, 10 Sep 2026 16:11:01 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=iRLrfN/V; spf=pass (domain: gmail.com, ip: 209.85.216.49, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f49.google.com with SMTP id 98e67ed59e1d1-38759bcd877so326901a91.2 for ; Thu, 10 Sep 2026 16:11:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081861; x=1789686661; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=NKDggtB136jimsWQPWbM2Db27CGGQwr4XREPuuHaPw4=; b=iRLrfN/VstgH/I8ZOZvoZTrZNADhwrgnRIsI5xivDWzAWwrfv0A9Xsc+Yt/d2i8Ab/ g5io2OMNT5+gTWeHmAR/SYHj3DkfQP/uCE/LyyGlbE3KpTXvG9khgkoE/X3u/S9OSi3y nqswcR1PimvVfz6fr4tJ30dNmJnyBEFGs7K4NPpbq6nCRfW0NCs2FI+CXt8VSgS/Htie HTSLXfKzt99fLCBnR8kuokmyvnakm2gPnJ6LBGZJzXcTlA0yblynowepQd/v5j9sWRJK czaslc1CS/cKyQJjtIIyL4P+rrh0HydtFedgXrsRVqEZJJmgyV+LmMZDJl5di0hMRaVF a2Uw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081861; x=1789686661; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=NKDggtB136jimsWQPWbM2Db27CGGQwr4XREPuuHaPw4=; b=C2Ag9MN71YbY0qE0+TzYWRLYn/kMHJq4HR38TdH3AfY/MQ6sAfGMiiYFNp6AtfKKG9 VoLgZYN1iLVciujKwr9NeL9LdjFXcr6zOMGTJ4bt/6bPs3lKqzuT8g8STWyqygNuD39d yNLW0N9dmOsqQzsHeJoPbyawkvSeCEasDC2vjC8R3FIcsf1D9J9e5V23M6vai0Vf+9Pu 98qcSt3UIAtKH+nN2OY90cc5gWpgc1MgQrKi92J4ywv80JcpPfkJ+T/XiUBiD3ikDjbV jueNgvZyVfJj0kuTZYRPJTOFvEaQeVSeRYREnR7Hyd2xn7RYU8JFvzj583RiSyJNwAWQ miYw== X-Gm-Message-State: AFuF++nIAPVP1rdcHuQ97P5bhYH0L0H+1wSHxcap8m9+gFjI1J1Zq4r7 3+JJ7rIofwNVTUgIGiLi5MqpKlGz6RxFFM8tPVUGEvv26kmJ4PGZUwc27k+EFQ== X-Gm-Gg: AYBFou18f4gmehlEq7N2QRHOsoB0gGczfI/f3DXc44B69yLQ6VMoAgMFswUkFiYOpXr Emgsc9r5vToEYbQNhUoNJ7q6/FQ6Np5XehlROY5JK8TO+SIwwkou7/zvQ8UTd1V6Rnc4W/Y2xUe B3Xyr9RYPd0kN3wmh5zzN5ethTclDOvM4C6gxGJ1s+sCSmB3vf6mKofVeepd4VPf0Lj6/woiPfE Q1qeL2QbKewJzFYbWRQpxfYi6+qkIoAWmXC2sF+U0x01tS/37Q9BiXadOWrr7GsoExiDiA9CVcb asn84wf0G94i1FZw1WksY66N2VOBcQO0Ifc6lt4YoAJ2UrtbbVUBYnVKevBlZtyp5MlSnMkzCRz nGESKAIwR6qTYr9euzlkty160sKxRANXSnzss9jOMsgkw8sdkex9b91khxnPwUtYwJAb2KuibeW Q0yDO29Qam0Q6HSMPv9l27OhEjPnE/tMV4YnTF7m8g8rNytj9nlSwxVKfy49KaNPbmne6mviG9I EYNRBEe8sHNztRCidm134OWjFJ/xUfM1w== X-Received: by 2002:a17:90b:57d0:b0:396:4dfb:5890 with SMTP id 98e67ed59e1d1-39d9bbd8781mr1827670a91.2.1789081861079; Thu, 10 Sep 2026 16:11:01 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.10.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:11:00 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 28/32] unbound: patch CVE-2026-55973 Date: Fri, 11 Sep 2026 11:09:27 +1200 Message-ID: <20260910230932.173913-28-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:11:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129946 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-55973 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-55973.patch | 47 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 48 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-55973.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-55973.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55973.patch new file mode 100644 index 0000000000..b463663af4 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55973.patch @@ -0,0 +1,47 @@ +From f7511787affcc7f1716f76dcc924c3880fc1f88a Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:18:16 +0200 +Subject: [PATCH] - Fix CVE-2026-55973, 'dns-error-reporting: yes' leads to + stack buffer overflow. Thanks to Qifan Zhang, Palo Alto Networks, for the + report. + +(cherry picked from commit 96f875552023c0ccf376ebe050519f12f3371dc9) + +CVE: CVE-2026-55973 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/96f875552023c0ccf376ebe050519f12f3371dc9] + +Signed-off-by: Ankur Tyagi +--- + services/cache/dns.c | 2 ++ + services/mesh.c | 4 ++-- + 2 files changed, 4 insertions(+), 2 deletions(-) + +diff --git a/services/cache/dns.c b/services/cache/dns.c +index 121870ee3..cb241c6f9 100644 +--- a/services/cache/dns.c ++++ b/services/cache/dns.c +@@ -259,6 +259,8 @@ find_closest_of_type(struct module_env* env, uint8_t* qname, size_t qnamelen, + + /* snip off front label */ + lablen = *qname; ++ if(lablen == 0) ++ break; + qname += lablen + 1; + qnamelen -= lablen + 1; + } +diff --git a/services/mesh.c b/services/mesh.c +index 191b1d488..432063c0d 100644 +--- a/services/mesh.c ++++ b/services/mesh.c +@@ -1620,9 +1620,9 @@ static void dns_error_reporting(struct module_qstate* qstate, + opt = edns_opt_list_find(qstate->edns_opts_back_in, + LDNS_EDNS_REPORT_CHANNEL); + if(!opt) return; +- agent_domain_len = opt->opt_len; + agent_domain = opt->opt_data; +- if(dname_valid(agent_domain, agent_domain_len) < 3) { ++ agent_domain_len = dname_valid(agent_domain, opt->opt_len); ++ if(agent_domain_len < 3) { + /* The agent domain needs to be a valid dname that is not the + * root; from RFC9567. */ + return; diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 0af51973cd..b867ea9b73 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -38,6 +38,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-54478.patch \ file://CVE-2026-55708.patch \ file://CVE-2026-55717.patch \ + file://CVE-2026-55973.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97920 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 19B32C88E48 for ; Thu, 10 Sep 2026 23:11:08 +0000 (UTC) Received: from mail-pj1-f42.google.com (mail-pj1-f42.google.com [209.85.216.42]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27790.1789081864545086245 for ; Thu, 10 Sep 2026 16:11:04 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=oVAldl+z; spf=pass (domain: gmail.com, ip: 209.85.216.42, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f42.google.com with SMTP id 98e67ed59e1d1-398a5aad413so281787a91.3 for ; Thu, 10 Sep 2026 16:11:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081864; x=1789686664; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=8rgtHO/0MXvxdhY6MBXE47kUB4UnMGerjMuXc45WOHY=; b=oVAldl+zNWNApDSxSop8imofXjS6qTH/3S0xiB/4+APoSLoI1WqCwcWQZ431rvoOe8 24ZP9n61PG85nU/64r7zLbV26wHrtzhamVXkmItBMu0KueLrNLppJOXSKkBEDDq1mKFi 8GMDuN5wtX+qKabrHAdpHdk+cVNpqNnHMZ++oaFmM+JJUNnXWNPfCXqJ6JQY3u7dLl5t 5hKtVTJQnYwmlkeAOYOk8heoO8B98Ff0m0NCEg6XskFsHqRTRIHEZl95f3zDPlyGfGgH hTgcKQY3uF/TSht9fqYiVPwRPCchEGRHHJkbPVU0zP4PZhyU+95eEkrt91hpJkOyzYh0 n5Mw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081864; x=1789686664; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=8rgtHO/0MXvxdhY6MBXE47kUB4UnMGerjMuXc45WOHY=; b=eNYArETwfeoXOJ2GcN1fXbLsVBRQormvwEk5G588OCSYqWtXUQTcsJc0BsYg9407fV 4NhA3kgPLiuMI9V5Sw1Nah/dIWZRuUoeoSH3VZZIcmAdb10vYBxqikmP8blkR/natVKr 4bBAMcr7Hx4WfqaNPNKPFwadWcwIi8rUFvy8/KLENA9ZZ5FWn+hheBzh5vLthBMeAmaM LIrfaemy5M0XyObcW4AtLp8pZMiVFVDY/5an66ypthNOyAEIVgpUF6xbrl42TAm9jYjz GdTDMUBzEmi5HkvO9cYj9zwywJjCp0w2HZEYJeBpgNPe9RkBchqALgWOVQa9Mwh1DaMK FTGA== X-Gm-Message-State: AFuF++lW4ojdcBCqPjx+Z/6/95ndd40dcTN6rOq0rK51KNzDRtc7g6b1 x6eVHRyIVYjk12JYBW8bMBLUQqq+NscH43TkUs8j/yq87FFvQ9O/4WyoPlGDpw== X-Gm-Gg: AYBFou12oWpcfnB2qX3HK/37YC2+IihIEXmWHEMS+dmwMazZQXoslwBE8SbavtQTghr g+B2CvgY+PIQh0s2PAoraAv9WI/PaiwUQEXAI5zUYDMf4+vZ2Jr1JG/9Xkwhkghg+3dYlYiieNi HRcVmmhJx8FoAA7OJHS/5/3hSmntE8rjhoMARKKgSbwSmzbITLsXhlGgYqpWx8JL5cjqVBkVG7x KykUhT9c85usk2M9qx1fCeGs4BJfe2GeA6aC1HxKTpASD1IyHqcWu56vWccV6wKsbBqrwe9+jTi tIqdB1KaPP+MZ9vWKyOFyYqmOk6Fq+mEDGniFSBv/rzCAvvAC/wFh+acITbcJOra80/zSBeCOoF WghOuZCddrtJ96Vt/QIaWDRM7EvVk8OyHhDxTJvtmdyuGd/X2R9r4YVMsCqrFBFk1XE1abVHqOY Bx6tMGNivMayn/JI0ShXgUxKMhOJq2UANkjayFIzYHXo5PAUZ+djwkmFRx4NNMBa9UGk3ZIcSqo JpAcMsjWhnh8uM7/okR5EAFx4OGCvgCmA== X-Received: by 2002:a17:90b:3885:b0:398:c794:ca26 with SMTP id 98e67ed59e1d1-39d9c3944aamr1569248a91.25.1789081863736; Thu, 10 Sep 2026 16:11:03 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.11.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:11:03 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 29/32] unbound: patch CVE-2026-55990 Date: Fri, 11 Sep 2026 11:09:28 +1200 Message-ID: <20260910230932.173913-29-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:11:08 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129947 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-55990 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-55990.patch | 59 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 60 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-55990.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-55990.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55990.patch new file mode 100644 index 0000000000..676f1aa17e --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55990.patch @@ -0,0 +1,59 @@ +From 6e6c039d23afb169991fa489c2010ab0069a2cab Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:18:41 +0200 +Subject: [PATCH] - Fix CVE-2026-55990, Packet of death for a DNSCrypt + misconfigured Unbound. Thanks to Qifan Zhang, Palo Alto Networks, for the + report. + +(cherry picked from commit ae1b3810cc3a8eb9b43c378289f74020b42aa7f4) + +CVE: CVE-2026-55990 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/ae1b3810cc3a8eb9b43c378289f74020b42aa7f4] + +Signed-off-by: Ankur Tyagi +--- + dnscrypt/dnscrypt.c | 12 +++++++++++- + 1 file changed, 11 insertions(+), 1 deletion(-) + +diff --git a/dnscrypt/dnscrypt.c b/dnscrypt/dnscrypt.c +index 173484cdf..bf858361f 100644 +--- a/dnscrypt/dnscrypt.c ++++ b/dnscrypt/dnscrypt.c +@@ -663,6 +663,8 @@ dnsc_find_cert(struct dnsc_env* dnscenv, struct sldns_buffer* buffer) + } + dnscrypt_header = (struct dnscrypt_query_header *)sldns_buffer_begin(buffer); + for (i = 0U; i < dnscenv->signed_certs_count; i++) { ++ if(!certs[i].keypair) ++ continue; + if (memcmp(certs[i].magic_query, dnscrypt_header->magic_query, + DNSCRYPT_MAGIC_HEADER_LEN) == 0) { + return &certs[i]; +@@ -804,6 +806,7 @@ dnsc_parse_keys(struct dnsc_env *env, struct config_file *cfg) + sizeof *env->keypairs); + env->certs = sodium_allocarray(env->signed_certs_count, + sizeof *env->certs); ++ memset(env->certs, 0, env->signed_certs_count * sizeof(*env->certs)); + + cert_id = 0U; + keypair_id = 0U; +@@ -963,12 +966,19 @@ dnsc_create(void) + int + dnsc_apply_cfg(struct dnsc_env *env, struct config_file *cfg) + { ++ int nkeys; + if(dnsc_parse_certs(env, cfg) <= 0) { + fatal_exit("dnsc_apply_cfg: no cert file loaded"); + } +- if(dnsc_parse_keys(env, cfg) <= 0) { ++ nkeys = dnsc_parse_keys(env, cfg); ++ if(nkeys <= 0) { + fatal_exit("dnsc_apply_cfg: no key file loaded"); + } ++ if((size_t)nkeys < env->signed_certs_count) { ++ fatal_exit("dnsc_apply_cfg: %u dnscrypt-provider-cert file(s) have no " ++ "matching dnscrypt-secret-key", ++ (unsigned)(env->signed_certs_count - (size_t)nkeys)); ++ } + randombytes_buf(env->hash_key, sizeof env->hash_key); + env->provider_name = cfg->dnscrypt_provider; + diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index b867ea9b73..e4d18e9b2a 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -39,6 +39,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-55708.patch \ file://CVE-2026-55717.patch \ file://CVE-2026-55973.patch \ + file://CVE-2026-55990.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:29 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97918 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id E4C17C88E45 for ; Thu, 10 Sep 2026 23:11:07 +0000 (UTC) Received: from mail-pj1-f43.google.com (mail-pj1-f43.google.com [209.85.216.43]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27869.1789081867194517504 for ; Thu, 10 Sep 2026 16:11:07 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=fwvMyPfs; spf=pass (domain: gmail.com, ip: 209.85.216.43, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f43.google.com with SMTP id 98e67ed59e1d1-398c1101c1bso302061a91.1 for ; Thu, 10 Sep 2026 16:11:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081866; x=1789686666; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=gdnK/+imx+9tRJ9YMx+Zo6+Kx5seHdxlPFYp3/xeLrI=; b=fwvMyPfssQBjZndfu0AKo6Qm1mbB6Ra8jObCTLDTdpr8NR97A/YNK9pEUgHb6fcWOj lMbkfmBxC0dbBnIQtGeIjiEMr3DTH2brjm7On0lFXuygQWV0DjgMDiYHpHjZb9o2eRve fCa+4VZ9uHHXHQMvdUBcWB53bdp5sJG64lqYibaYJA0yHUEcooiPGhHy4Pcs8+g5gqYV lNYH9kTmxonNtGlaSAMfZRhzb34lJrSCDFMmH5MgOXICGRqQoAo3nXHZIcPewqVwkQbF 7ubn/lVGqUZWdYVOQye0Gi5PeIHyE1shyWr1SvteLqeOCLf6nlAvlig3/cPRvUcWsoXB yJxA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081866; x=1789686666; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=gdnK/+imx+9tRJ9YMx+Zo6+Kx5seHdxlPFYp3/xeLrI=; b=mahIkO4EtXsUzhvHIJI6lMuvMCgxNiuAtpJVJTEn1FE3qBVrm21SOhhcxOf0iBtQDb kCx0bNW/Jir94v+ZBsBKFnBs8EU11H4r0zcTdqZI04DVATEVJlM2IVGGBod3SF1aHr6q 6wFL4Bfylv7PvWvjSTAy3bYlyuJjVLn7Z33cxpVn9IETXGSI7TwTyQlgmRoL4te6DJwo 0K5+I+gCnTX3fPxa63fjinLwUOT/6lGZcv3+qDeJdvga8MyCR5Fc8Cn1fmRp8nPjpyFA DJ1jlAHCt2Eh2QQAQP9H5y20zziVgWZQLM2ngQXWNZkCGn4/xCxGK28+jsUhafW5lheG WepQ== X-Gm-Message-State: AFuF++libypji099NAUV81yn40k9UAK22plYl6R2RKWHlLGNRoadiQrf S57a7pNkBZiwcGd+F1BHiYTB2unvslbHrM/nShJI7KSdAFQ4iAX1tA8P+bbAqA== X-Gm-Gg: AYBFou3E1Hz5XyFzYEyApPsTNTwY5rSXdHTSJRhr9DSZ6fH94ZnrlumE8KD1+sUyqid Jm4OylSOK4i0PzKdILGvo3pnzsOrya6LZDTYm4yfgFZ3y9lAQIv6mZX32QFZK07Sn5xVVG/Yv0j Wx0hAsTaKra97WY7wyW8StQbj4z3yq9xi+fWpAP7YTWr/Ihp8p8H3H7hO8/zrxt+5OpnrHHeJCe /DYrTuuyLL8KBsKyHf9sc1OtpFbIeZzB2cp1aXCrlLfvPxJftbJttOnhOpKo8tBQEw2ldTTq2Js hi2heB7aHvKBDiTAjHdJe+cqR+6x+fgD2gLMvynJvjKkQg3LfQ9bPYzBp8XOYsVYoGqD+LvIicn dy5BvGMSgPtSCYpyHGe3QRFRSVJQfDpT5CmV+qSuOE/brw82HGIcDTi0/uVi5CxFovGlWqp299y 2BD16JgwPp7pqxAIoNuA+7lcDjhUrrc+SE8tlOBT59jpmXhOwV9Y9beFKyYNoheHgYtF9S/spX7 ShmCbr8/1HcfKiwByZa+J0= X-Received: by 2002:a17:90b:5605:b0:38f:7f60:ba35 with SMTP id 98e67ed59e1d1-39d9bbd8837mr1590090a91.5.1789081866408; Thu, 10 Sep 2026 16:11:06 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.11.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:11:06 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 30/32] unbound: patch CVE-2026-55991 Date: Fri, 11 Sep 2026 11:09:29 +1200 Message-ID: <20260910230932.173913-30-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:11:07 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129948 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-55991 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-55991.patch | 112 ++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 113 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-55991.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-55991.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55991.patch new file mode 100644 index 0000000000..7946f5a59f --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-55991.patch @@ -0,0 +1,112 @@ +From 355213b9175382db5e86e49731aa939a533b1b03 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:19:02 +0200 +Subject: [PATCH] - Fix CVE-2026-55991, Remote DNS-over-QUIC (DoQ) flow-control + assertion failure in libngtcp2. Thanks to Qifan Zhang, Palo Alto + Networks, for the report. In addition, thanks to Xuanchao Xie, for also + reporting this issue. + +(cherry picked from commit aac261cbb3795cbd60af2f37ef57bfa5c186aae6) + +CVE: CVE-2026-55991 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/aac261cbb3795cbd60af2f37ef57bfa5c186aae6] + +Signed-off-by: Ankur Tyagi +--- + services/listen_dnsport.c | 46 +++++++++++++++++++++++++++------------ + testcode/doqclient.c | 4 ++-- + 2 files changed, 34 insertions(+), 16 deletions(-) + +diff --git a/services/listen_dnsport.c b/services/listen_dnsport.c +index 3c5010b6b..d49d4ad4c 100644 +--- a/services/listen_dnsport.c ++++ b/services/listen_dnsport.c +@@ -4472,6 +4472,29 @@ doq_stream_reset_cb(ngtcp2_conn* ATTR_UNUSED(conn), int64_t stream_id, + return 0; + } + ++/** ngtcp2 extend_max_stream_data function */ ++int doq_extend_max_stream_data_cb(ngtcp2_conn* ATTR_UNUSED(conn), ++ int64_t stream_id, uint64_t max_data, void* user_data, ++ void* ATTR_UNUSED(stream_user_data)) ++{ ++ struct doq_conn* doq_conn = (struct doq_conn*)user_data; ++ struct doq_stream* stream; ++ verbose(VERB_ALGO, "doq extend_max_stream_data stream id %d " ++ "max_data %d ", (int)stream_id, (int)max_data); ++ if(max_data == 0) ++ return 0; ++ stream = doq_stream_find(doq_conn, stream_id); ++ if(!stream) { ++ verbose(VERB_ALGO, "doq: unknown stream %d", (int)stream_id); ++ return 0; ++ } ++ if(!stream->is_answer_available) ++ return 0; ++ doq_stream_on_write_list(doq_conn, stream); ++ doq_conn_write_enable(doq_conn); ++ return 0; ++} ++ + /** ngtcp2 acked_stream_data_offset callback function */ + static int + doq_acked_stream_data_offset_cb(ngtcp2_conn* ATTR_UNUSED(conn), +@@ -4846,6 +4869,7 @@ doq_conn_setup(struct doq_conn* conn, uint8_t* scid, size_t scidlen, + callbacks.stream_open = doq_stream_open_cb; + callbacks.stream_close = doq_stream_close_cb; + callbacks.stream_reset = doq_stream_reset_cb; ++ callbacks.extend_max_stream_data = doq_extend_max_stream_data_cb; + callbacks.acked_stream_data_offset = doq_acked_stream_data_offset_cb; + callbacks.recv_stream_data = doq_recv_stream_data_cb; + +@@ -5427,26 +5451,20 @@ doq_conn_write_streams(struct comm_point* c, struct doq_conn* conn, + continue; + } else if(ret == NGTCP2_ERR_STREAM_DATA_BLOCKED) { + verbose(VERB_ALGO, "doq: ngtcp2_conn_writev_stream returned NGTCP2_ERR_STREAM_DATA_BLOCKED"); +-#ifdef HAVE_NGTCP2_CCERR_DEFAULT +- ngtcp2_ccerr_set_application_error( +- &conn->ccerr, -1, NULL, 0); +-#else +- ngtcp2_connection_close_error_set_application_error(&conn->last_error, -1, NULL, 0); +-#endif +- if(err_drop) +- *err_drop = 0; +- if(!doq_conn_close_error(c, conn)) { +- if(err_drop) +- *err_drop = 1; ++ if(stream) { ++ doq_stream_off_write_list(conn, stream); ++ stream = stream->write_next; ++ continue; ++ } else { ++ break; + } +- return 0; + } else if(ret == NGTCP2_ERR_STREAM_SHUT_WR) { + verbose(VERB_ALGO, "doq: ngtcp2_conn_writev_stream returned NGTCP2_ERR_STREAM_SHUT_WR"); + #ifdef HAVE_NGTCP2_CCERR_DEFAULT + ngtcp2_ccerr_set_application_error( +- &conn->ccerr, -1, NULL, 0); ++ &conn->ccerr, DOQ_APP_ERROR_CODE, NULL, 0); + #else +- ngtcp2_connection_close_error_set_application_error(&conn->last_error, -1, NULL, 0); ++ ngtcp2_connection_close_error_set_application_error(&conn->last_error, DOQ_APP_ERROR_CODE, NULL, 0); + #endif + if(err_drop) + *err_drop = 0; +diff --git a/testcode/doqclient.c b/testcode/doqclient.c +index 1994cd097..3cb25c98b 100644 +--- a/testcode/doqclient.c ++++ b/testcode/doqclient.c +@@ -1519,9 +1519,9 @@ doq_client_send_pkt(struct doq_client_data* data, uint32_t ecn, uint8_t* buf, + } + log_err("doq sendmsg: %s", strerror(errno)); + #ifdef HAVE_NGTCP2_CCERR_DEFAULT +- ngtcp2_ccerr_set_application_error(&data->ccerr, -1, NULL, 0); ++ ngtcp2_ccerr_set_application_error(&data->ccerr, 1, NULL, 0); + #else +- ngtcp2_connection_close_error_set_application_error(&data->last_error, -1, NULL, 0); ++ ngtcp2_connection_close_error_set_application_error(&data->last_error, 1, NULL, 0); + #endif + return 0; + } diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index e4d18e9b2a..af848988aa 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -40,6 +40,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-55717.patch \ file://CVE-2026-55973.patch \ file://CVE-2026-55990.patch \ + file://CVE-2026-55991.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:30 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97923 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1F42DC88E41 for ; Thu, 10 Sep 2026 23:11:18 +0000 (UTC) Received: from mail-pj1-f41.google.com (mail-pj1-f41.google.com [209.85.216.41]) by mx.groups.io with SMTP id smtpd.msgproc01-g2.27870.1789081869844839239 for ; Thu, 10 Sep 2026 16:11:09 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=TlzKpp6J; spf=pass (domain: gmail.com, ip: 209.85.216.41, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f41.google.com with SMTP id 98e67ed59e1d1-398a5aad413so281832a91.3 for ; Thu, 10 Sep 2026 16:11:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081869; x=1789686669; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=H2UsNTZTCbxP3VVBKasiC5N+37ohbcAmCzxMd6QfSiM=; b=TlzKpp6JCxu3QUXfezPArEBJdvQbOoC+/M80kdqMVuIgrLC4a1XI14GRSt3nAlr3Jp nsOhEz8n5dPCKi0qQE21PdHwKuQsIfML7P/1DrfTZSGVLa/Z/rf+ocigc7SWoMvVcdkN icXRQ3Ep/LZjqFV06opwYZUy+3kSIUdDmEJ2fbVy3mlzjiSojM7WRKuzqUL4eiFE2N4v 8KE5twbKPhmbuGFX+uvhW49Z3UGbdY53ElMLKm/SU8WM+fUjV7cJlKT9hVRY9+RJlEDz Rt7OvskRH5jO2KYwdz7JxEn0VfQGuvt7QjHY+cbUheTjgOJxamWumsg81oSf0QfKfxGw rX+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081869; x=1789686669; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=H2UsNTZTCbxP3VVBKasiC5N+37ohbcAmCzxMd6QfSiM=; b=AvpfzfUcxrdxXdNWZBKIAncsdgh3uI5CT/bSNs94vB9abCGB5PKQ/WCN6xFWeu/Xan kcagjKalwWgMhcdTTVQS5wpFpoUnXsmgS14LJFM9UbLwOHZCfkzWFHG7yOQBddOiCtVl nUmCShr6S9AD2JeasF80+qkZhYugYG4WG4yBu5/8GEEcz6JseY3MztL3BKW62tIRFs72 1ad3z+Iew9qjGFwqvrG3rAKQU8GnDoctYDXStJQCPXqdJFTeIYn2ZkGmPDvSjWI3Q7ad RWJ44x0bsxC91xY3gy1WOdf+xBgvgyqQ4CSaZsfniksM/94N2l2DIRcSuE4HqDaVqkZQ I7yA== X-Gm-Message-State: AFuF++lMr5XUu52aymJnuXRV3kwr0wVWfrJaSzQ6kX88Uh4D1m57s8zg w0HBHhUvhMSWCDolACJVgyqv8f+1GXFPw7oS3JPiTy/4DNQBUz6gCbJ8xPzq7Q== X-Gm-Gg: AYBFou21Ct1tFi/FF4kzObxM/lpu+sKu8SxQBi6mcrLmBfsntmVcE1KY8rqy3bQuqBj j6/N/+msYSKYR0FT94OVkLTXSSGM3UDKD+Yx+Tll/KbWyFHWRvMEfjMDadZ3RaptHC/Jy1r97cE vEqfAOuHoJyL9iHPkM/M+ptH/8GRDSgsf5Ktrl3anY4A4X9xtRkBwRS0fIIsupKcuWbSJ/0hysE cciLANh0oWHMs7sRHfLBYTc5wMLpexJpbj84i9b0gcmBUNhQCrjI4+3ku6WOLSC4//DAj9qUz1u tFr8wHXCV5H5ilTcgt9NsOBt2XYj9z2ZUWnOyrRD0HyMLJJAr8e+DxSiZ4lIOn+GgYknnpbj8Ty p7cEaKdI5cD/3/ldlzvMzZdrE9G+rj5zbCqg2ITVPhY4F3ul7ijLs3HFRJ2YDsDMj8UW+Gt3sGd pQWR75yGdPWbki+A1QE82B8zoQJiRYuQKsqC+bNmQaaZ2jmC7Nz1Cz8e2HOJEpMOgLyR7wofNA2 wwaQXyZ6f/lBvgQiNgQMCc= X-Received: by 2002:a17:90b:4cce:b0:38e:7168:281 with SMTP id 98e67ed59e1d1-39d9bec4d91mr1756634a91.10.1789081869143; Thu, 10 Sep 2026 16:11:09 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.11.06 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:11:08 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 31/32] unbound: patch CVE-2026-56416 Date: Fri, 11 Sep 2026 11:09:30 +1200 Message-ID: <20260910230932.173913-31-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:11:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129949 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-56416 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-56416.patch | 68 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 69 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-56416.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-56416.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-56416.patch new file mode 100644 index 0000000000..6002c44924 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-56416.patch @@ -0,0 +1,68 @@ +From 984cbdd8761685087f1e20d6e9d9da12d7412916 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:19:28 +0200 +Subject: [PATCH] - Fix CVE-2026-56416, Possible heap buffer overflow when + validator canonicalizes RDATA that contains domain name. Thanks to Qifan + Zhang, Palo Alto Networks, for the report. + +(cherry picked from commit 4b1635e19406fd8040806f0fa4a4488c003b5d0d) + +CVE: CVE-2026-56416 +Upstream-Status: Backport [https://github.com/NLnetLabs/unbound/commit/4b1635e19406fd8040806f0fa4a4488c003b5d0d] + +Signed-off-by: Ankur Tyagi +--- + util/data/msgparse.c | 3 +++ + validator/val_sigcrypt.c | 11 +++++++---- + 2 files changed, 10 insertions(+), 4 deletions(-) + +diff --git a/util/data/msgparse.c b/util/data/msgparse.c +index 3dc2e1264..9d3ddda7a 100644 +--- a/util/data/msgparse.c ++++ b/util/data/msgparse.c +@@ -687,6 +687,9 @@ calc_size(sldns_buffer* pkt, uint16_t type, struct rr_parse* rr) + } + rdf++; + } ++ /* rdata ended before all _dname_count names were seen */ ++ if(count != 0) ++ return 0; /* the rdata is too short. */ + } + /* remaining rdata */ + rr->size += pkt_len; +diff --git a/validator/val_sigcrypt.c b/validator/val_sigcrypt.c +index 86de6fb8e..cde281870 100644 +--- a/validator/val_sigcrypt.c ++++ b/validator/val_sigcrypt.c +@@ -1094,6 +1094,7 @@ canonicalize_rdata(sldns_buffer* buf, struct ub_packed_rrset_key* rrset, + size_t len) + { + uint8_t* datstart = sldns_buffer_current(buf)-len+2; ++ size_t firstlen; + switch(ntohs(rrset->rk.type)) { + case LDNS_RR_TYPE_NXT: + case LDNS_RR_TYPE_NS: +@@ -1113,8 +1114,9 @@ canonicalize_rdata(sldns_buffer* buf, struct ub_packed_rrset_key* rrset, + case LDNS_RR_TYPE_SOA: + /* two names after another */ + query_dname_tolower(datstart); +- query_dname_tolower(datstart + +- dname_valid(datstart, len-2)); ++ firstlen = dname_valid(datstart, len-2); ++ if(firstlen && firstlen < len-2) ++ query_dname_tolower(datstart + firstlen); + return; + case LDNS_RR_TYPE_RT: + case LDNS_RR_TYPE_AFSDB: +@@ -1141,8 +1143,9 @@ canonicalize_rdata(sldns_buffer* buf, struct ub_packed_rrset_key* rrset, + return; + datstart += 2; + query_dname_tolower(datstart); +- query_dname_tolower(datstart + +- dname_valid(datstart, len-2-2)); ++ firstlen = dname_valid(datstart, len-2-2); ++ if(firstlen && firstlen < len-2-2) ++ query_dname_tolower(datstart + firstlen); + return; + case LDNS_RR_TYPE_NAPTR: + if(len < 2+4) diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index af848988aa..516ea20654 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -41,6 +41,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-55973.patch \ file://CVE-2026-55990.patch \ file://CVE-2026-55991.patch \ + file://CVE-2026-56416.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c" From patchwork Thu Sep 10 23:09:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ankur Tyagi X-Patchwork-Id: 97922 X-Patchwork-Delegate: anuj.mittal@oss.qualcomm.com Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2C4ABC79FBB for ; Thu, 10 Sep 2026 23:11:18 +0000 (UTC) Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) by mx.groups.io with SMTP id smtpd.msgproc02-g2.27795.1789081872439366264 for ; Thu, 10 Sep 2026 16:11:12 -0700 Authentication-Results: mx.groups.io; dkim=pass header.i=@gmail.com header.s=20251104 header.b=Y1smSbuo; spf=pass (domain: gmail.com, ip: 209.85.216.53, mailfrom: ankur.tyagi85@gmail.com) Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-38759bcd877so326986a91.2 for ; Thu, 10 Sep 2026 16:11:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789081872; x=1789686672; darn=lists.openembedded.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=P3J8rAU3qxfoWFSJD1DlA62B9wfvxdowfguTRWCcFKc=; b=Y1smSbuo1sLyQViEvHjBto7W8E5/nXx/JUU9hqF30d4dljxnYfajf7zC4ERrYJ2xUb wZSFLCEKnufCGrS2EIrRVpIviYCFJikliz1Rm1WG/mAKe14WOIKbmE+EuKKk+9xQY66h IQQ/iCI89v8RQrezZXIGgQKDcsK+/DEZhs82YEnlvsY7IOg4cCYBnXPHemRJHYERN4R9 O/NTsLBxkSZpDowzuRKgVnzYVXW9C7cVUqwqx9+EWSCEpPptpCw4OXzLs1Z2sUKV0gJJ mN0IzD9TZWztjfg23WiOai88lhTVrQoHSrZ8i0emJgw2K/JaXT1Wjxn2vrhprNvPBm71 W2Zg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789081872; x=1789686672; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=P3J8rAU3qxfoWFSJD1DlA62B9wfvxdowfguTRWCcFKc=; b=i7nLXrspvP+0l1vMAn3zOEG90vRiNy0vyt7PCQJGu1WZAfn+GDrZvDO/wHG+3g10zk ze31fx+XW6ZA9mTwjG6/AEKqHf+8A6BiJ8uAxdhBD01TC7IUE9K2IDT05IL14CcJb0OQ xQGMkn3udKn78DV/6TaSZNMu3squqRhCAvozXqXFjwGOHuWe+Qi3soxfDEMczDk7k7ja yR0A5auSvJLJgmZ7/J8Fw+m18TvpRo8CskFCGUvBUqsjx+zpvw5aG+lesGHXrp2uNax4 HykKezI60fV+2TXaBr87B75QzwHrY7iz8duLEP0dzoZ1mkbSeXrJYxf9QoWGdKrIinO7 k2Ww== X-Gm-Message-State: AFuF++l/z4SWtxcPSkJL7TpdIOHcRj4LC9yjfk9PDxZon6JiYKz7MfR7 wrazkdT9K9uM2b8ih7iqpRkZ07+zHLtxyeAkbaO8gGvHpJv5uF8tbwywgEaXoA== X-Gm-Gg: AYBFou1ldJHxT+5vh4KCAhmNWoG06eLk1UtLXFHP2GiZ/wQ/D24ZNNC5GcwBQKjxrGC S6GeSvBkKcXXvWwOrhVtoCmJuivd8qVnx5qI9A/4BjNNdxkKrNvwlYe7Nk4pUrJBWXRHnMVrzxN 68/U28Nx1G/ned81WVFklDaUsSmDbP4m4mnFD+XwGjMTTo7qhFR2Cja56750PxdaMpc7Bk3F8Be VGe1Fjs7YZNhUcnZ4oIo7iFvRgU+1Ij7eqAo94IH35465Gti06qVfAiaDEuK4cE2CR5M8eexoyJ fNX5AP/fNEhEbo1mi+cUaKs7DVFaDTIpgojIh1yJpY/jAbIQ3t2Dim6/kREZfGW6lZKyyI2gHTE eKk/W19nwwW2yT/rQN7TOQk9gO/7vQAzND3uLd75hs4C+RYiJjCksY2efg5/3pizdCHI2eeXnMV NvSnoy0Z9OOztrtsAs+F+Dvw08vv2GAa77sVcztAINHWmFcBN+qn0Dz3pa/Z+1beK5nDLO4hPNj 79XAKydJyplJrl4HUs0h18= X-Received: by 2002:a17:90b:4b82:b0:396:5fce:8e24 with SMTP id 98e67ed59e1d1-39d9bbd881fmr1802383a91.4.1789081871720; Thu, 10 Sep 2026 16:11:11 -0700 (PDT) Received: from NVAPF55DW0D-IPD.. ([203.211.104.195]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39d98e602d8sm1265496a91.3.2026.09.10.16.11.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 10 Sep 2026 16:11:11 -0700 (PDT) From: ankur.tyagi85@gmail.com To: openembedded-devel@lists.openembedded.org Cc: Ankur Tyagi Subject: [oe][meta-networking][wrynose][PATCH 32/32] unbound: patch CVE-2026-56444 Date: Fri, 11 Sep 2026 11:09:31 +1200 Message-ID: <20260910230932.173913-32-ankur.tyagi85@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260910230932.173913-1-ankur.tyagi85@gmail.com> References: <20260910230932.173913-1-ankur.tyagi85@gmail.com> MIME-Version: 1.0 List-Id: X-Webhook-Received: from 45-33-107-173.ip.linodeusercontent.com [45.33.107.173] by aws-us-west-2-korg-lkml-1.web.codeaurora.org with HTTPS for ; Thu, 10 Sep 2026 23:11:18 -0000 X-Groupsio-URL: https://lists.openembedded.org/g/openembedded-devel/message/129950 From: Ankur Tyagi Details: https://nvd.nist.gov/vuln/detail/cve-2026-56444 Signed-off-by: Ankur Tyagi --- .../unbound/unbound/CVE-2026-56444.patch | 51 +++++++++++++++++++ .../recipes-support/unbound/unbound_1.24.2.bb | 1 + 2 files changed, 52 insertions(+) create mode 100644 meta-networking/recipes-support/unbound/unbound/CVE-2026-56444.patch diff --git a/meta-networking/recipes-support/unbound/unbound/CVE-2026-56444.patch b/meta-networking/recipes-support/unbound/unbound/CVE-2026-56444.patch new file mode 100644 index 0000000000..e851bb4f12 --- /dev/null +++ b/meta-networking/recipes-support/unbound/unbound/CVE-2026-56444.patch @@ -0,0 +1,51 @@ +From 200cd7322d9462025b1d2b9f3e1fe5383735a6c6 Mon Sep 17 00:00:00 2001 +From: "W.C.A. Wijngaards" +Date: Wed, 22 Jul 2026 10:19:50 +0200 +Subject: [PATCH] - Fix CVE-2026-56444, Degradation of resolution service when + 'discard-timeout' and 'serve-expired-client-timeout' are combined in + unusual configuration. Thanks to Qifan Zhang, Palo Alto Networks, for the + report. In addition, thanks to Xin Wang, Jiapeng Li, and Jiajia Liu, + Northwestern Polytechnical University, for also reporting this issue. In + addition, thanks to Haruki Oyama (Waseda University), for also reporting + this issue. + +(cherry picked from commit 84d9682dd0876bc0cd118ecce03661f3443b0222) + +CVE: CVE-2026-56444 +Upstream-Status:Backport [https://github.com/NLnetLabs/unbound/commit/84d9682dd0876bc0cd118ecce03661f3443b0222] + +Signed-off-by: Ankur Tyagi +--- + services/mesh.c | 10 +++++++--- + 1 file changed, 7 insertions(+), 3 deletions(-) + +diff --git a/services/mesh.c b/services/mesh.c +index 432063c0d..a6798953e 100644 +--- a/services/mesh.c ++++ b/services/mesh.c +@@ -2505,9 +2505,10 @@ mesh_serve_expired_callback(void* arg) + log_dns_msg("Serve expired lookup", &qstate->qinfo, msg->rep); + + for(r = mstate->reply_list; r; r = r->next) { +- struct timeval old; +- timeval_subtract(&old, mstate->s.env->now_tv, &r->start_time); +- if(mstate->s.env->cfg->discard_timeout != 0 && ++ if(mesh_is_udp(r)) { ++ struct timeval old; ++ timeval_subtract(&old, mstate->s.env->now_tv, &r->start_time); ++ if(mstate->s.env->cfg->discard_timeout != 0 && + ((int)old.tv_sec)*1000+((int)old.tv_usec)/1000 > + mstate->s.env->cfg->discard_timeout) { + /* Drop the reply, it is too old */ +@@ -2525,8 +2526,11 @@ mesh_serve_expired_callback(void* arg) + http2_stream_remove_mesh_state(r->h2_stream); + comm_point_drop_reply(&r->query_reply); + mstate->reply_list = reply_list; ++ log_assert(mstate->s.env->mesh->num_reply_addrs > 0); ++ mstate->s.env->mesh->num_reply_addrs--; + mstate->s.env->mesh->num_queries_discard_timeout++; + continue; ++ } + } + + i++; diff --git a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb index 516ea20654..faf315876c 100644 --- a/meta-networking/recipes-support/unbound/unbound_1.24.2.bb +++ b/meta-networking/recipes-support/unbound/unbound_1.24.2.bb @@ -42,6 +42,7 @@ SRC_URI = "git://github.com/NLnetLabs/unbound.git;protocol=https;branch=master;t file://CVE-2026-55990.patch \ file://CVE-2026-55991.patch \ file://CVE-2026-56416.patch \ + file://CVE-2026-56444.patch \ " SRCREV = "f6269baa605d31859f28770e01a24e3677e5f82c"