Unnamed repository
Bug reported bt Royce M <royce@xchglabs.com>
Location: helper.c:265-270
DHCPv6 CLIDs can be up to 65535 bytes. When --dhcp-script is configured,
the helper hex-encodes raw CLID bytes via sprintf("%.2x") into daemon->packet (5131 bytes).
A 1000-byte CLID writes ~3000 bytes. The helper process retains root privileges.
Note: log6_packet() correctly caps CLID to 100 bytes for logging, but the helper code path was missed.
Resolves-Vulnerability: CVE-2026-4892
Resolves: RHEL-168313
|
||
|---|---|---|
| .fmf | ||
| .gitignore | ||
| ci.fmf | ||
| dnsmasq-2.77-underflow.patch | ||
| dnsmasq-2.78-fips.patch | ||
| dnsmasq-2.81-configuration.patch | ||
| dnsmasq-2.86-build_server_array.patch | ||
| dnsmasq-2.93-CVE-2026-2291.patch | ||
| dnsmasq-2.93-CVE-2026-4890.patch | ||
| dnsmasq-2.93-CVE-2026-4891.patch | ||
| dnsmasq-2.93-CVE-2026-4892.patch | ||
| dnsmasq-CVE-2026-2291.patch | ||
| dnsmasq-systemd-sysusers.conf | ||
| dnsmasq.service | ||
| dnsmasq.spec | ||
| gating.yaml | ||
| nm.fmf | ||
| plans.fmf | ||
| rpminspect.yaml | ||
| sources | ||
| srkgpg.txt | ||
| test-release-public-key | ||
| tmpfiles-dnsmasq.conf | ||