[9.18] [CVE-2026-11331] sec: usr: Fix handling of rpz CNAME expansion that returns name too long Previously, if the expansion of a wildcard CNAME RPZ policy resulted in a name that exceeded the length limit, a self referential CNAME and the original address record were returned, allowing the policy to be bypassed. In branches up to 9.20, this also left query processing in an inconsistent state which could trigger an assertion failure. We now return a YXDOMAIN response, without the address. ISC would like to thank Laith Mash'al (0xmshal) for bringing this issue to our attention. Closes https://gitlab.isc.org/isc-projects/bind9/-/issues/5856
31 lines
995 B
Diff
31 lines
995 B
Diff
From 49f4cc4e93f14f1d5b6a472124e6aa457167fede Mon Sep 17 00:00:00 2001
|
|
From: Mark Andrews <marka@isc.org>
|
|
Date: Fri, 10 Apr 2026 10:26:14 +1000
|
|
Subject: [PATCH] Properly handle rpz name to long wildcard expansion
|
|
|
|
Previously a self referential CNAME and the original address
|
|
record were returned. We now return a YXDOMAIN response.
|
|
|
|
(cherry picked from commit cfc4c4f69870ce492deaaa429453563d1621ded3)
|
|
(cherry picked from commit dc328a199f96222e0c30cc20b7b795bfc2c9b2e4)
|
|
---
|
|
lib/ns/query.c | 3 ++-
|
|
1 file changed, 2 insertions(+), 1 deletion(-)
|
|
|
|
diff --git a/lib/ns/query.c b/lib/ns/query.c
|
|
index d3a10be9ba..3bd7daf79c 100644
|
|
--- a/lib/ns/query.c
|
|
+++ b/lib/ns/query.c
|
|
@@ -7591,7 +7591,8 @@ query_rpzcname(query_ctx_t *qctx, dns_name_t *cname) {
|
|
qctx->fname, NULL);
|
|
if (result == DNS_R_NAMETOOLONG) {
|
|
client->message->rcode = dns_rcode_yxdomain;
|
|
- } else if (result != ISC_R_SUCCESS) {
|
|
+ }
|
|
+ if (result != ISC_R_SUCCESS) {
|
|
return result;
|
|
}
|
|
} else {
|
|
--
|
|
2.55.0
|
|
|