Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • That is pretty bad!

    "a remote attacker capable of asking DNS queries or answering DNS queries can cause a large OOB write in the heap."

    Malformed DNS response causes "infinite loop and dnsmasq stops responding to all queries."

    Malicious DHCP request can cause buffer overlow.

  • How bad is it if someone infects my home router using such a thing? They can MITM non-encrypted requests, but there are not a lot of those, right?

    What else can they do, assuming the computers behind the router are all patched up.

  • Shameless plug time:

    My own MaraDNS has been extensively audited now that we’re in the age of AI-assisted security audits.

    Not one single serious security bug has been found since 2023. [1]

    The only bugs auditers have been finding are things like “Deadwood, when fully recursive, will take longer than usual to release resources when getting this unusual packet” [2] or “This side utility included with MaraDNS, which hasn’t been able to be compiled since 2022, has a buffer overflow, but only if one’s $HOME is over 50 characters in length” [3]

    I’m actually really pleased just how secure MaraDNS is now that it’s getting real in depth security audits.

    [1] https://samboy.github.io/MaraDNS/webpage/security.html

    [2] https://github.com/samboy/MaraDNS/discussions/136

    [3] https://github.com/samboy/MaraDNS/pull/137

  • Has OpenWRT released a new build yet?

    Answer: no, but they're working on it.

    https://forum.openwrt.org/t/dnsmasq-set-of-serious-cves/2500...

  • To quote a famous (in certain circles) bowl of petunias, "oh no, not again!"
  • It's a good thing this software isn't used in millions of devices which almost never receive updates.
  • I think this is the breaking point where replacing our code written in C for code written in memory safe languages is becoming urgent.

    The vast majority of vulnerabilities found recently are directly related to being written in memory unsafe languages, it's very difficult to justify that a DNS/DHCP server can't be written in rust or go and without using unsafe (well, maybe a few unsafe calls are still needed, but these will be a very small amount)...

Explore Birbla archives

CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq · Birbla