diff --git a/bind-9.21-resume-qmin-cname.patch b/bind-9.21-resume-qmin-cname.patch new file mode 100644 index 0000000..05fd4b4 --- /dev/null +++ b/bind-9.21-resume-qmin-cname.patch @@ -0,0 +1,44 @@ +From ac0c3b0477d97fe5c968910f603bb8d04c740da7 Mon Sep 17 00:00:00 2001 +From: Petr Mensik +Date: Tue, 3 Jun 2025 21:00:58 +0200 +Subject: [PATCH] Handle CNAME and DNAME in resume_min in a special way + +When authoritative zone is loaded when query minimization query for the +same zone is already pending, it might receive unexpected result codes. + +Normally DNS_R_CNAME would follow to query_cname after processing sent +events, but dns_view_findzonecut does not fill CNAME target into +event->foundevent. Usual lookup via query_lookup would always have that +filled. + +Ideally we would restart the query with unmodified search name, if +unexpected change from recursing to local zone cut were detected. Until +dns_view_findzonecut is modified to export zone/cache source of the cut, +at least fail queries which went into unexpected state. +--- + lib/dns/resolver.c | 9 +++++++++ + 1 file changed, 9 insertions(+) + +diff --git a/lib/dns/resolver.c b/lib/dns/resolver.c +index 795791246b..39a294437e 100644 +--- a/lib/dns/resolver.c ++++ b/lib/dns/resolver.c +@@ -4497,6 +4497,15 @@ resume_qmin(isc_task_t *task, isc_event_t *event) { + if (result == DNS_R_NXDOMAIN) { + result = DNS_R_SERVFAIL; + } ++ /* ++ * CNAME or DNAME means zone were added with that record ++ * after the start of query minimization queries. It means ++ * we do not have initialized correct hevent->foundname ++ * and have to fail. ++ */ ++ if (result == DNS_R_CNAME || result == DNS_R_DNAME) { ++ result = DNS_R_SERVFAIL; ++ } + + if (result != ISC_R_SUCCESS) { + goto cleanup; +-- +2.49.0 + diff --git a/bind9.18.spec b/bind9.18.spec index 29865f3..cf72614 100644 --- a/bind9.18.spec +++ b/bind9.18.spec @@ -77,7 +77,7 @@ License: MPL-2.0 AND ISC AND MIT AND BSD-3-Clause AND BSD-2-Clause # ./lib/isc/tm.c BSD-2-clause and/or MPL-2.0 # ./lib/isccfg/parser.c BSD-2-clause and/or MPL-2.0 Version: 9.18.29 -Release: 3%{?dist} +Release: 4%{?dist} Epoch: 32 Url: https://www.isc.org/downloads/bind/ # @@ -124,6 +124,10 @@ Patch30: bind-9.18-CVE-2024-11187-pre-test.patch Patch31: bind-9.18-CVE-2024-11187.patch # https://gitlab.isc.org/isc-projects/bind9/-/commit/e733e624147155d6cbee7f0f150c79c7ac6b54bb Patch32: bind-9.18-CVE-2024-12705.patch +# https://gitlab.isc.org/isc-projects/bind9/-/merge_requests/10562 +# https://gitlab.isc.org/isc-projects/bind9/-/issues/5357 +# downstream patch fixing bind-dyndb-ldap causing issue +Patch33: bind-9.21-resume-qmin-cname.patch %{?systemd_ordering} Requires: coreutils @@ -971,6 +975,9 @@ fi; %endif %changelog +* Tue Jun 10 2025 Petr Mensik - 32:9.18.29-4 +- Prevent name.c:670 attributes assertion failed (RHEL-30407) + * Mon Feb 03 2025 Petr Menšík - 32:9.18.29-3 - Limit additional section records CPU processing (CVE-2024-11187) - Read HTTPS requests in limited chunks and prevent overload (CVE-2024-12705)