-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: dnsmasq security update
Advisory ID:       RHSA-2021:0154-01
Product:           Red Hat Enterprise Linux
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:0154
Issue date:        2021-01-19
CVE Names:         CVE-2020-25684 CVE-2020-25685 CVE-2020-25686 
====================================================================
1. Summary:

An update for dnsmasq is now available for Red Hat Enterprise Linux 7.7
Extended Update Support.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Relevant releases/architectures:

Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - x86_64
Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - x86_64
Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64

3. Description:

The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name
Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.

Security Fix(es):

* dnsmasq: loose address/port check in reply_query() makes forging replies
easier for an off-path attacker (CVE-2020-25684)

* dnsmasq: loose query name check in reply_query() makes forging replies
easier for an off-path attacker (CVE-2020-25685)

* dnsmasq: multiple queries forwarded for the same name makes forging
replies easier for an off-path attacker (CVE-2020-25686)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

4. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

5. Bugs fixed (https://bugzilla.redhat.com/):

1889686 - CVE-2020-25684 dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker
1889688 - CVE-2020-25685 dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker
1890125 - CVE-2020-25686 dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker

6. Package List:

Red Hat Enterprise Linux ComputeNode EUS (v. 7.7):

Source:
dnsmasq-2.76-10.el7_7.2.src.rpm

x86_64:
dnsmasq-2.76-10.el7_7.2.x86_64.rpm
dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm

Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7):

x86_64:
dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm
dnsmasq-utils-2.76-10.el7_7.2.x86_64.rpm

Red Hat Enterprise Linux Server EUS (v. 7.7):

Source:
dnsmasq-2.76-10.el7_7.2.src.rpm

ppc64:
dnsmasq-2.76-10.el7_7.2.ppc64.rpm
dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64.rpm

ppc64le:
dnsmasq-2.76-10.el7_7.2.ppc64le.rpm
dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64le.rpm

s390x:
dnsmasq-2.76-10.el7_7.2.s390x.rpm
dnsmasq-debuginfo-2.76-10.el7_7.2.s390x.rpm

x86_64:
dnsmasq-2.76-10.el7_7.2.x86_64.rpm
dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm

Red Hat Enterprise Linux Server Optional EUS (v. 7.7):

ppc64:
dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64.rpm
dnsmasq-utils-2.76-10.el7_7.2.ppc64.rpm

ppc64le:
dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64le.rpm
dnsmasq-utils-2.76-10.el7_7.2.ppc64le.rpm

s390x:
dnsmasq-debuginfo-2.76-10.el7_7.2.s390x.rpm
dnsmasq-utils-2.76-10.el7_7.2.s390x.rpm

x86_64:
dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm
dnsmasq-utils-2.76-10.el7_7.2.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/

7. References:

https://access.redhat.com/security/cve/CVE-2020-25684
https://access.redhat.com/security/cve/CVE-2020-25685
https://access.redhat.com/security/cve/CVE-2020-25686
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/security/vulnerabilities/RHSB-2021-001

8. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYAblv9zjgjWX9erEAQhqbw/8CmQI7lftuhRZBmU3VadwuiKa2WxqV96g
1dP7wqfand0peKs4NRZmz8VdnlJm/NaZNfltWJ52prrtp57nLzK3hpM8BtRVBSnY
0a9Yd2+7XJs58OUJuwlZFx1M3E/iRuz7HnjkYIU3e9AGV7e+tNE3YOvuhxBLuEcA
fKeWO++NVjlC1wfeOywKo4ICDk4RXYQh+BKvXLpHpXWqNYjoAiPcgmxwLdLjuLp2
YyOLNHevb3iYaLw0krToMaXvvjBk8KwQcUSUvRKhZ0/qzZ9f638+qbKWlyb3QLVp
NJCoT9fJ7/gGXedaUhE+s0TMehNt2dzNsdBntoR0vYWsVt9jZBo+sCwBFr+6Fct2
sxUhlyEVPepgs5IJ/rF/xGMWE7jxxXgP1ZPdYKsI1JB+KAXOOz6sQkLww7BbWnAS
B0pTJzp132Q4mOnaOrjpzD3tsrOw/WburDfQLIVIO5p56KJQ6Dr5m7/Z9aUds8mt
Bw7Rs1XLWnFZRlmOo2L7NfBkNTI1FdQAh2zxBURv4SlJAL7jnP2DskmffmAHFYaf
T2obXT02RaqEv6L6QmWl/m4knqDMOn+2N10vTMkKES7SlRWwTQ77a/WScQyvYjDd
rtuDuScW3kRF4maROoDC5Kl/DzABs2SQmGw2/iowrsmVKXd87w51/JUmAMx/97pX
N64nqQ2htwg=q9/8
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2021-0154:01 Moderate: dnsmasq security update

An update for dnsmasq is now available for Red Hat Enterprise Linux 7.7 Extended Update Support

Summary

The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.
Security Fix(es):
* dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25684)
* dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker (CVE-2020-25685)
* dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker (CVE-2020-25686)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-25684 https://access.redhat.com/security/cve/CVE-2020-25685 https://access.redhat.com/security/cve/CVE-2020-25686 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2021-001

Package List

Red Hat Enterprise Linux ComputeNode EUS (v. 7.7):
Source: dnsmasq-2.76-10.el7_7.2.src.rpm
x86_64: dnsmasq-2.76-10.el7_7.2.x86_64.rpm dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7):
x86_64: dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm dnsmasq-utils-2.76-10.el7_7.2.x86_64.rpm
Red Hat Enterprise Linux Server EUS (v. 7.7):
Source: dnsmasq-2.76-10.el7_7.2.src.rpm
ppc64: dnsmasq-2.76-10.el7_7.2.ppc64.rpm dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64.rpm
ppc64le: dnsmasq-2.76-10.el7_7.2.ppc64le.rpm dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64le.rpm
s390x: dnsmasq-2.76-10.el7_7.2.s390x.rpm dnsmasq-debuginfo-2.76-10.el7_7.2.s390x.rpm
x86_64: dnsmasq-2.76-10.el7_7.2.x86_64.rpm dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm
Red Hat Enterprise Linux Server Optional EUS (v. 7.7):
ppc64: dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64.rpm dnsmasq-utils-2.76-10.el7_7.2.ppc64.rpm
ppc64le: dnsmasq-debuginfo-2.76-10.el7_7.2.ppc64le.rpm dnsmasq-utils-2.76-10.el7_7.2.ppc64le.rpm
s390x: dnsmasq-debuginfo-2.76-10.el7_7.2.s390x.rpm dnsmasq-utils-2.76-10.el7_7.2.s390x.rpm
x86_64: dnsmasq-debuginfo-2.76-10.el7_7.2.x86_64.rpm dnsmasq-utils-2.76-10.el7_7.2.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/


Severity
Advisory ID: RHSA-2021:0154-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:0154
Issued Date: : 2021-01-19
CVE Names: CVE-2020-25684 CVE-2020-25685 CVE-2020-25686

Topic

An update for dnsmasq is now available for Red Hat Enterprise Linux 7.7Extended Update Support.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures

Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - x86_64

Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - x86_64

Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64

Red Hat Enterprise Linux Server Optional EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64


Bugs Fixed

1889686 - CVE-2020-25684 dnsmasq: loose address/port check in reply_query() makes forging replies easier for an off-path attacker

1889688 - CVE-2020-25685 dnsmasq: loose query name check in reply_query() makes forging replies easier for an off-path attacker

1890125 - CVE-2020-25686 dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker


Related News