From 446f7c38487cece5d236a6c3f956833b085c2622 Mon Sep 17 00:00:00 2001 From: Martin Hoffmann Date: Fri, 25 Sep 2026 15:34:49 +0200 Subject: [PATCH 1/2] Advisory for domain 0.12.3. --- crates/domain/RUSTSEC-0000-0000.md | 63 ++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) create mode 100644 crates/domain/RUSTSEC-0000-0000.md diff --git a/crates/domain/RUSTSEC-0000-0000.md b/crates/domain/RUSTSEC-0000-0000.md new file mode 100644 index 000000000..b1bfdc73f --- /dev/null +++ b/crates/domain/RUSTSEC-0000-0000.md @@ -0,0 +1,63 @@ +```toml +[advisory] +id = "RUSTSEC-0000-0000" +package = "domain" +date = "2026-09-25" +url = "https://github.com/NLnetLabs/domain/releases/tag/v0.12.3" +# See https://docs.rs/rustsec/latest/rustsec/advisory/enum.Category.html +categories = ["denial-of-service"] + +[versions] +patched = [">= 0.12.3"] +``` + +# Various panics, soundness and resource exhaustion issues + +Version 0.12.3 fixes a large number of panics, soundness issues, and +CPU and memory exhaustion issues in all parts of the crate. + +The following is a summary of the issues per affected components. +For details, please see the [release +notes](https://github.com/NLnetLabs/domain/releases/tag/v0.12.3). + +## Base + +* Limited the number of compression pointers that are followed when parsing + a compressed name to 255 to avoid following really long chains. +* Limited the length of CNAME chains followed by `Message::canonical_name` + to 20. This also fixed an integer overflow in this method when ANCOUNT + was`u16::MAX`. +* Changed `QuestionSection::answer` to skip over all remaining questions + without parsing the QNAMEs to avoid being slowed down by malicious + names. +* Added length checks when scanning and parsing variable length record + data types. + +## Stub Resolver + +* Fixed possible panics in the resolver’s `FoundHosts::qname` and + `FoundHosts::canonical_name`. +* Fixed various issues in SRV processing. + +## Zonefile parsing + +* Fixed soundness issues when reading UTF-8 and an integer overflow when + reading unsigned integers. +* Fixed a panic when reading empty TXT records. + +## Client and server transports, DNSSEC signer and validator + +Fixed various panics that could be triggered by malicious incoming DNS +messages. + +## Zonetree + +Fixed various panics and a memory exhaustion issue when updating the zone. + +## Acknowledgements + +We would like to thank Qifan Zhang, Palo Alto Networks, +Antoni (Tony) Jagodka ([@DrVelvetFog](https://github.com/DrVelvetFog)), +and [@SebastiaanYN](https://github.com/SebastiaanYN) for +reporting issues fixed in this release. + From b11b3b0be9379ee86a17d20aab5a20f918e7bfb0 Mon Sep 17 00:00:00 2001 From: Martin Hoffmann Date: Fri, 25 Sep 2026 15:50:40 +0200 Subject: [PATCH 2/2] Explain length checks a bit more. --- crates/domain/RUSTSEC-0000-0000.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/crates/domain/RUSTSEC-0000-0000.md b/crates/domain/RUSTSEC-0000-0000.md index b1bfdc73f..edf3320af 100644 --- a/crates/domain/RUSTSEC-0000-0000.md +++ b/crates/domain/RUSTSEC-0000-0000.md @@ -31,7 +31,8 @@ notes](https://github.com/NLnetLabs/domain/releases/tag/v0.12.3). without parsing the QNAMEs to avoid being slowed down by malicious names. * Added length checks when scanning and parsing variable length record - data types. + data types. This fixes issues with the message builder, which assumes that + record data is never too large for placing in a message. ## Stub Resolver