10 ms·
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
- romaniitedomum 5mo agoTo quote a famous (in certain circles) bowl of petunias, "oh no, not again!"
- antod 5mo agoAre you saying this is Arthur Dent's fault? (again)
- BLKNSLVR 5mo agoFor a number of reasons, I feel that the only way we got here was via some kind of infinite improbability drive. (mostly unrelated to topic at hand though)
- romaniitedomum 5mo ago> For a number of reasons, I feel that the only way we got here was via some kind of infinite improbability drive. Oh very much so! In my mind, it seems that someone must have figured out what the universe was for, and now it's been replaced with something even more bizarre and inexplicable.
- BLKNSLVR 5mo ago"Oh, I see you've discovered subatomic particles... here, have some quantum phenomena, see how long that keeps you busy"
- 882542F3884314B 5mo agohttps://xchglabs.com/blog/dnsmasq-five-cves.html https://xchglabs.com/blog/dnsmasq-five-cves.html
- Tacite 5mo agoThanks, Claude ! :)
- washingupliquid 5mo agoIt's a good thing this software isn't used in millions of devices which almost never receive updates.
- amiga386 5mo agoIt's more of a good thing that, in most cases, it's on devices that won't send it any packets unless a client first authenticates to a Wi-Fi station or physically plugs into an Ethernet port.
- leptons 5mo agoY2K26?
- BLKNSLVR 5mo agoWhen the contraction became longer than the standard notation.
- JamesSwift 5mo agoIts lame now, just season passes and loot boxes
- tuetuopay 5mo agoWell, it is a good thing to get control of your own hardware, when the vendor decides that no you won't do what you want with it.
- dist-epoch 5mo agoHow bad is it if someone infects my home router using such a thing? They can MITM non-encrypted requests, but there are not a lot of those, right? What else can they do, assuming the computers behind the router are all patched up.
- nhattruongadm 5mo ago[flagged]
- zrm 5mo agoThey can block traffic to update servers so the computers behind the router aren't all patched up, then exploit them. They also get access to all the IoT devices on the internal network. They can also use your router as a proxy so their scraping/attack traffic comes from your IP address instead of theirs. It's definitely bad.
- PhilipRoman 5mo agoIf you blindly TOFU ssh sessions, those can be pwned easily in many common use cases. Legacy software configurations like NFS with IP authentication will be bypassed. Realistically the most likely scenario is using your home as a VPN, or a DDOS node.
- raggi 5mo agoyeah, and it's not like people recently launched a coffee shop that accepts payments over tofu ssh and a shell provider doing the same
- Asmod4n 5mo agothey could try and exploit any device on your network, and since they see which servers you connect to and how often you communicate with one they can write phishing mails which are tailored just for you.
- washingupliquid 5mo agoMaybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes. But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it. Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broken packages before, because fixing it would somehow make it not "stable". They would rather ship useless, broken code than something too new. It's crazy.
- zrm 5mo agoThey're not going to put a newer version in stable. The way stable gets newer versions of things is that you get the newer version into testing and then every two years testing becomes stable and stable becomes oldstable, at which point the newer version from testing becomes the version in stable. The thing to complain about is if the version in testing is ancient.
- wolttam 5mo agoLooks like the version in stable is 2.91, which was released within a couple months of trixie. It's not 'ancient' by any stretch. FWIW the fixes referenced here are already fixed in trixie: https://security-tracker.debian.org/tracker/source-package/dnsmasq https://security-tracker.debian.org/tracker/source-package/d...
- braiamp 5mo agoYeah was about to comment, parent says "if it is ancient", it is not. So the root comment is nothing burger. Stable has 1 release cycle old, and depending on how things play out, testing may have 2.93 or later anyways.
- PunchyHamster 5mo ago2.92 currently
- 5mo ago
- xydac 5mo agosome of these would have made to embedded hardwares, making updates more challenging if say you were to flash an update.
- ck2 5mo agoif machine-learning can find all these holes why can't machine-learning write a product from scratch that is flawless?
- yjftsjthsd-h 5mo agoWho said it can't? https://news.ycombinator.com/item?id=47759709 https://news.ycombinator.com/item?id=47759709 appears to be a nearly flawless (per spec) zip implementation.
- PunchyHamster 5mo ago[flagged]
- yjftsjthsd-h 5mo agoNo, a collection of fuzzers and the lean proof assistant found (almost) no bugs.
- dang 5mo agoCould you please stop breaking the site guidelines? We've already asked you once. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- PunchyHamster 5mo agoSorry, I got carried away, the whole blind trust in AI tools gets me wound up a bit too fast, I'll try to be better. > We've already asked you once. there are no notifications of any kind about that or the fact the comment has been flagged so I genuinely didn't notice previous one and only noticed this after I noticed rate limiting.
- _flux 5mo agoJust because something is good at finding bugs, it may not find all the bugs. Finding a bug only tells you there was one bug you found, it doesn't tell if the rest is solid.
- strenholme 5mo agoShameless plug time: My own MaraDNS has been extensively audited now that we’re in the age of AI-assisted security audits. Not one single serious security bug has been found since 2023. [1] The only bugs auditers have been finding are things like “Deadwood, when fully recursive, will take longer than usual to release resources when getting this unusual packet” [2] or “This side utility included with MaraDNS, which hasn’t been able to be compiled since 2022, has a buffer overflow, but only if one’s $HOME is over 50 characters in length” [3] I’m actually really pleased just how secure MaraDNS is now that it’s getting real in depth security audits. [1] https://samboy.github.io/MaraDNS/webpage/security.html https://samboy.github.io/MaraDNS/webpage/security.html [2] https://github.com/samboy/MaraDNS/discussions/136 https://github.com/samboy/MaraDNS/discussions/136 [3] https://github.com/samboy/MaraDNS/pull/137 https://github.com/samboy/MaraDNS/pull/137
- binaryturtle 5mo agoThat's a bit shameless, indeed. dnsmasq has served me well for like an eternity in multiple setups for different use cases. As all software it has bugs. And once located those get fixed. Its author is also easy to communicate with. Why should I switch over to something way less proven? I'm quite sure your software also has bugs, many still not located. Maybe because it's less popular/ less well known nobody cares to hunt for those bugs? Which means even if the numbers of found bugs is less in your software at the moment, and it may look more audited for this reason, it may actually be way less secure.
- rgkpz 5mo ago"All software has bugs" is the most meaningless statement ever. It is just used for bonding with fellow bug writers who sit at a virtual campfire and muse about inevitabilities. Demonstrably some software has fewer bugs, and its authors are often hated, especially if they are a lone author like Bernstein. Because it must not happen! Projects with useless churn and many bug reports are more popular because only activity matters, not quality.
- zamadatix 5mo ago
- cedum 5mo ago[dead]
- mrbluecoat 5mo ago> The tsunami of AI-generated bug reports shows no signs of stopping, so it is likely that this process will have to be repeated again soon. Welcome to the new world order.
- rela-12w987 5mo agoThe AI bug report tsunami is not in all projects. As the top comment notes, MaraDNS didn't have any. I assume djbdns and tinydns didn't either, otherwise they'd shout it from the rooftops. I never understood why some projects get extremely popular and others don't. I also suspect by now that the reports by tools that are "too dangerous to release" scan all projects but selectively only contact those with issues, so that they never have to admit that their tool didn't find anything.
- philipwhiuk 5mo ago> The AI bug report tsunami is not in all projects. It's in popular projects.
- 3ASAF 5mo agoNo, postfix hasn't had a single valid bug found by AI. There are legions of other projects as well. It is a distorted view, because projects become popular by allowing indiscriminate commits, bugs, maintainers. If I'd start a new project I'd allow anyone in and blog about 100 exploits every year, because that is exactly what people want. I'm serious.
- tscburak 5mo ago[flagged]
- SoftTalker 5mo agoNever liked using dnsmasq. Always felt like too much in one tool. A local caching resolver, dhcp server, and tftp/pxe boot setup were always things I preferred to configure separately.
- cwillu 5mo agoThat line of thinking is exactly why I ended up using maradns for my dns hosting way back. 10/10, no regrets, would recommend.
- magicalhippo 5mo agoWhat do you use for DHCP and how do you have DHCP update local DNS entries? Or do you just rely on mDNS to work?
- SoftTalker 5mo agoI use dhcpd. It doesn't update local DNS entries. I have no need for that.
- cwillu 5mo agoI use maradns to provide dns, not to resolve it. My vps does not require its own dhcp server.
- koyote 5mo agoI agree, it also goes against the Linux "way of doing things". For example, Opnsense uses the dhcp portions of dnsmasq only (and unbound for the dns parts) which just feels 'wrong'.
- gerdesj 5mo agoWhen I first came across Linux you would download the code (very slowly) to /usr/src/linux (extract and cd) and run "make config". You'd answer quite a lot of y/n and later y/n/m questions and then copy a binary and later on run a script to put things in place. Then you would fix up lilo and off you trot ... or not 8) Is that the Linux way you are on about? No obviously not 8) I think you mean the "unix idealized but never really happened exactly but we are quite close if you squint a bit ... way" where each tool does one job well and the pipeline takes up the slack.
- aftbit 5mo agoHas OpenWRT released a new build yet? Answer: no, but they're working on it. https://forum.openwrt.org/t/dnsmasq-set-of-serious-cves/250061/8 https://forum.openwrt.org/t/dnsmasq-set-of-serious-cves/2500...
- leptons 5mo agoDD-WRT is also on point... https://github.com/mirror/dd-wrt/issues/465 https://github.com/mirror/dd-wrt/issues/465 https://svn.dd-wrt.com/changeset/64944 https://svn.dd-wrt.com/changeset/64944 https://svn.dd-wrt.com/changeset/64905 https://svn.dd-wrt.com/changeset/64905 The release is "coming soon".
- theamk 5mo agoThat is pretty bad! "a remote attacker capable of asking DNS queries or answering DNS queries can cause a large OOB write in the heap." Malformed DNS response causes "infinite loop and dnsmasq stops responding to all queries." Malicious DHCP request can cause buffer overlow.
- unclejuan 5mo agoI think this is the breaking point where replacing our code written in C for code written in memory safe languages is becoming urgent. The vast majority of vulnerabilities found recently are directly related to being written in memory unsafe languages, it's very difficult to justify that a DNS/DHCP server can't be written in rust or go and without using unsafe (well, maybe a few unsafe calls are still needed, but these will be a very small amount)...
- x3n0ph3n3 5mo agoI disagree -- we're clearly getting better safeguards by way of AI agents to spot potential vulnerabilities!
- nullsanity 5mo ago[dead]
- jabl 5mo agoThe question is whether the current situation is a short burst of action, and once those most critical bugs get fixed the hype around AI vulnerability scanning will die down, or whether the current crop of system/infra software written in vulnerable languages like C are beyond redemption and they will provide an endless source of critical bugs for AI to find until we fix them by rewriting them in Rust/Go/whatever.
- 1vuio0pswjnm7 5mo agoI never liked dnsmasq or the Pi-Hole dderivation and do not use it but many people seem to love this software. I don't think there is any amount of CVEs that could convince people to stop using it
- thenickdude 5mo agoLXD uses dnsmasq to provide DHCP and DNS for containers I think? Viable container escape?
- sailfast 5mo ago"hopefully they will be releasing patched versions of their dnsmasq packages in a timely manner." Hopefully!
- PeterStuer 5mo ago"The tsunami of AI-generated bug reports shows no signs of stopping, so it is likely that this process will have to be repeated again soon." But, ai-deniers are telling us there is nothing to see ...
- Baltazhar 5mo agoWhat is the nature of these findings? There’s a big difference between AI finding a buffer overflow vs. identifying a fundamental protocol flaw. Could AI realistically discover something like the Kaminsky attack? or even something which is an amplification exploit like the NXNSAttack?
- deleted 5mo ago[deleted]
- Memalloc 5mo agoHow about fixing the defective MMU ? CVE-2026-2291 Heap buffer overflow, Infinite loop, Integer underflow, Heap buffer overflow ..
- asa400 5mo agoFor folks with more experience in this specific domain, dumb question: why is more software in this space not written in e.g. Erlang or some other garbage collected, concurrent language runtime?
- LtWorf 5mo agoIn C you can normally directly map struct to network packets so that's quite easy. In other languages it's not often as simple. Plus of course they are slower and bigger.
- jerf 5mo agoThe initial release of dnsmasq was in 2001. The list of viable languages for a high-performance network server at the time was still not all that long. Erlang wasn't on it. Too big a performance hit, too much opaque runtime that may not have been stable at the time, too few contributors, big dependency footprint of stuff most things wouldn't have installed. (When I used Erlang for a production system in more like the 2015 time frame it still had rough corners if you weren't using it exactly for the use case it was meant for.) This isn't specially a criticism of Erlang, it would have been like this across many languages and runtimes. A lot of these systems that are getting hit, and will probably continue to be hit over the next few weeks or months, have a similar story. The Linux kernel's only other potentially viable choice was C++ at the time. OpenSSL, a perennial security offender, was started in 1998. You can look up your own favorite major system library with major security issues and it's probably the same story. I'm as aggressive as anyone about saying "don't write a new project in C for network access", but cast me back to 1998 and I couldn't tell you what other viable choices there are either. There are safer languages, but they were much, much smaller than the C community, and I couldn't promise you how stable they were either. Java was out, and I don't know when to draw the exact line as to when it became a serious contender for a network server, but late 200Xs would be my guess; certainly what I saw in 1999 wasn't yet. Example: I ran a Haskell network server in 2011 for something relatively unimportant and it fell over under conditions that would not have been very extreme for a production network; I know it was Haskell and not my code because I reused the same code base in 2013 with no changes in the core run loop and it did about 90% better; still not enough that I would have put that system into a real production use case but enough to show it wasn't my code failing. So while Haskell may have existed in the 200Xs, it wouldn't have qualified as a viable choice for a network server at the time. There's a lot more viable choices today than there used to be.
- darig 5mo ago[dead]