From 262aadd7a38947d2299234c8c9cf736ff6ad955d Mon Sep 17 00:00:00 2001 From: Simon Kelley Date: Wed, 25 Mar 2026 23:22:37 +0000 Subject: [PATCH] Fix broken client subnet validation. CVE-2026-4893 Bug report from Royce M Location: forward.c:713, edns0.c:421 With --add-subnet enabled, process_reply() passes the OPT record length (~23 bytes) instead of the packet length to check_source(). All internal bounds checks fail, and the function always returns 1. ECS source validation per RFC 7871 Section 9.2 is completely bypassed. CVE: CVE-2026-4893 Upstream-Status: Backport [https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=e3a26d092e47bf1d18aeadb758e4ca35c83b5f2d] Signed-off-by: Hugo SIMELIERE (Schneider Electric) --- src/forward.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/forward.c b/src/forward.c index 32f37e40..19ff4401 100644 --- a/src/forward.c +++ b/src/forward.c @@ -710,7 +710,7 @@ static size_t process_reply(struct dns_header *header, time_t now, struct server /* Get extended RCODE. */ rcode |= sizep[2] << 4; - if (option_bool(OPT_CLIENT_SUBNET) && !check_source(header, plen, pheader, query_source)) + if (option_bool(OPT_CLIENT_SUBNET) && !check_source(header, n, pheader, query_source)) { my_syslog(LOG_WARNING, _("discarding DNS reply: subnet option mismatch")); return 0; -- 2.43.0