GHSA-5j98-2g5x-46v6: High severity rust/hickory-resolver vulnerability
When calling Resolver::lookup() or Resolver::lookupip() on a resolver with DNSSEC validation enabled, both methods return Ok(...) if DNSSEC validation fails. It is possible but very inconvenient to check the validation status of individual records. These methods should instead return an error when DNSSEC validation determines a response is bogus.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rust/hickory-resolverto a version that resolves this vulnerability.Fixed in 0.26.2
Event History
Frequently Asked Questions
Which deployments are exposed?
Deployments using rust/hickory-resolver that enable DNSSEC validation and call Resolver::lookup() or Resolver::lookup_ip() are affected. The risk is greatest where callers treat an Ok result as confirmation that DNSSEC validation succeeded.
What does an attacker need to exploit this issue?
The supplied severity vector indicates network attack access, low attack complexity, no required privileges, and no user interaction. The issue is relevant when DNSSEC validation identifies a response as bogus but the lookup API still returns Ok.
Can an application detect the validation failure despite receiving Ok?
Yes, the validation status of individual records can be checked, but the advisory describes doing so as very inconvenient. The affected lookup methods themselves do not return an error when validation determines the response is bogus.