[Buildroot] [PATCH 2017.02.x] musl: add upstream security fix for CVE-2017-15650

Peter Korsgaard peter at korsgaard.com
Wed Oct 25 07:41:33 UTC 2017


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > From the upstream announcement:
 > http://www.openwall.com/lists/oss-security/2017/10/19/5

 > Felix Wilhelm has discovered a flaw in the dns response parsing for
 > musl libc 1.1.16 that leads to overflow of a stack-based buffer.
 > Earlier versions are also affected.

 > When an application makes a request via getaddrinfo for both IPv4 and
 > IPv6 results (AF_UNSPEC), an attacker who controls or can spoof the
 > nameservers configured in resolv.conf can reply to both the A and AAAA
 > queries with A results. Since A records are smaller than AAAA records,
 > it's possible to fit more addresses than the precomputed bound, and a
 > buffer overflow occurs.

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2017.02.x, thanks.

-- 
Bye, Peter Korsgaard


More information about the buildroot mailing list