Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Red Hat 8 RHSA-2021:0150-01 Important Dnsmasq Buffer Overflow

red hat
Calendar Grey January 19, 2021
Dist Redhat Esm H88
The latest security patch from Red Hat for dnsmasq tackles several significant vulnerabilities aimed at enhancing both robustness and safety.
An update for dnsmasq is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.
Security Fix(es):
* dnsmasq: heap-based buffer overflow in sort_rrset() when DNSSEC is enabled (CVE-2020-25681)
* dnsmasq: buffer overflow in extract_name() due to missing length check when DNSSEC is enabled (CVE-2020-25682)
* dnsmasq: heap-based buffer overflow with large memcpy in get_rdata() when DNSSEC is enabled (CVE-2020-25683)
* dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25684)
* dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25685)
* dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker (CVE-2020-25686)
* dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset() when DNSSEC is enabled (CVE-2020-25687)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2020-25681 https://access.redhat.com/security/cve/CVE-2020-25682 https://access.redhat.com/security/cve/CVE-2020-25683 https://access.redhat.com/security/cve/CVE-2020-25684 https://access.redhat.com/security/cve/CVE-2020-25685 https://access.redhat.com/security/cve/CVE-2020-25686 https://access.redhat.com/security/cve/CVE-2020-25687 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/RHSB-2021-001

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: dnsmasq-2.79-13.el8_3.1.src.rpm
aarch64: dnsmasq-2.79-13.el8_3.1.aarch64.rpm dnsmasq-debuginfo-2.79-13.el8_3.1.aarch64.rpm dnsmasq-debugsource-2.79-13.el8_3.1.aarch64.rpm dnsmasq-utils-2.79-13.el8_3.1.aarch64.rpm dnsmasq-utils-debuginfo-2.79-13.el8_3.1.aarch64.rpm
ppc64le: dnsmasq-2.79-13.el8_3.1.ppc64le.rpm dnsmasq-debuginfo-2.79-13.el8_3.1.ppc64le.rpm dnsmasq-debugsource-2.79-13.el8_3.1.ppc64le.rpm dnsmasq-utils-2.79-13.el8_3.1.ppc64le.rpm dnsmasq-utils-debuginfo-2.79-13.el8_3.1.ppc64le.rpm
s390x: dnsmasq-2.79-13.el8_3.1.s390x.rpm dnsmasq-debuginfo-2.79-13.el8_3.1.s390x.rpm dnsmasq-debugsource-2.79-13.el8_3.1.s390x.rpm dnsmasq-utils-2.79-13.el8_3.1.s390x.rpm dnsmasq-utils-debuginfo-2.79-13.el8_3.1.s390x.rpm
x86_64: dnsmasq-2.79-13.el8_3.1.x86_64.rpm dnsmasq-debuginfo-2.79-13.el8_3.1.x86_64.rpm dnsmasq-debugsource-2.79-13.el8_3.1.x86_64.rpm dnsmasq-utils-2.79-13.el8_3.1.x86_64.rpm dnsmasq-utils-debuginfo-2.79-13.el8_3.1.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2021:0150-01
Product: Red Hat Enterprise Linux
Issue date: 2021-01-19

Topic

An update for dnsmasq is now available for Red Hat Enterprise Linux 8.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64

Bugs Fixed

1881875 - CVE-2020-25681 dnsmasq: heap-based buffer overflow in sort_rrset() when DNSSEC is enabled

1882014 - CVE-2020-25682 dnsmasq: buffer overflow in extract_name() due to missing length check when DNSSEC is enabled

1882018 - CVE-2020-25683 dnsmasq: heap-based buffer overflow with large memcpy in get_rdata() when DNSSEC is enabled

1889686 - CVE-2020-25684 dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker

1889688 - CVE-2020-25685 dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker

1890125 - CVE-2020-25686 dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker

1891568 - CVE-2020-25687 dnsmasq: heap-based buffer overflow with large memcpy in sort_rrset() when DNSSEC is enabled

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here