REDHAT-BUG-2458517: High severity Nlnet Labs Unbound vulnerability
In validaterrset() at dnssec.c:546, siglen is calculated as rdlen - (p - psav) without checking that rdlen is large enough to cover the fixed RRSIG fields and signer name. A crafted RRSIG with a short rdlen makes siglen go negative, which when passed as a size parameter becomes a huge unsigned value, causing a massive heap OOB read. Fix: check siglen <= 0 and return STATBOGUS before using it.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In validate_rrset() at dnssec.c:546, after computing sig_len as rdlen - (p - psav), add a check that sig_len <= 0 and immediately return STAT_BOGUS before passing sig_len as a size parameter to prevent huge unsigned wraparound and heap OOB reads.
dnssec.c (validate_rrset) sig_len bounds check = if (sig_len <= 0) return STAT_BOGUS before using sig_len as a size parameter
Event History
Frequently Asked Questions
What input condition causes the unsafe length calculation?
A crafted RRSIG record whose rdlen is too short to cover the fixed RRSIG fields and signer name can make the calculated signature length negative.
What happens after the fix detects an invalid signature length?
The validator treats a signature length of zero or less as bogus and returns STAT_BOGUS before the value is used as a size parameter.