]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
fix: usr: Fix read UAF in BIND9 dns_client_resolve() via DNAME Response
authorOndřej Surý <ondrej@isc.org>
Fri, 20 Feb 2026 11:51:41 +0000 (12:51 +0100)
committerOndřej Surý <ondrej@isc.org>
Fri, 20 Feb 2026 11:51:41 +0000 (12:51 +0100)
An attacker controlling a malicious DNS server returns a DNAME record,
and the we stores a pointer to resp->foundname, frees the response
structure, then uses the dangling pointer in dns_name_fullcompare()
possibly causing invalid match.  Only the `delv`is affected.  This has
been fixed.

Closes #5728

Merge branch '5728-heap-uaf-in-bind9-dns_client_resolve-via-dname-response' into 'main'

See merge request isc-projects/bind9!11570


Trivial merge