Skip to content

fix(dnssec): validate short RSA DNSKEY blobs#59

Open
deepin-ci-robot wants to merge 1 commit into
deepin-community:masterfrom
deepin-ci-robot:backport/fix-dnssec-validate-short-rsa-dnskey
Open

fix(dnssec): validate short RSA DNSKEY blobs#59
deepin-ci-robot wants to merge 1 commit into
deepin-community:masterfrom
deepin-ci-robot:backport/fix-dnssec-validate-short-rsa-dnskey

Conversation

@deepin-ci-robot

Copy link
Copy Markdown
Contributor

Summary

Backport upstream fix to validate short RSA DNSKEY blobs in the DNSSEC resolver. Rejects malformed RSA DNSKEY data before reading the extended exponent header, preventing potential out-of-bounds read.

Changes

  • Add debian/patches/fix-dnssec-validate-short-rsa-dnskey.patch
  • Modify debian/patches/series
  • Modify debian/changelog

Upstream

systemd/systemd@004401fd

Generated-By: glm-5-turbo
Co-Authored-By: jiabowen jiabowen@uniontech.com

Reject malformed RSA DNSKEY data before reading the extended exponent
header, and add a regression test.

Co-developed-by: GitHub Copilot (GPT 5.5) <copilot@github.com>

Changes:
  - Add debian/patches/fix-dnssec-validate-short-rsa-dnskey.patch
  - Modify debian/patches/series
  - Modify debian/changelog

Upstream: systemd/systemd@004401f

Generated-By: glm-5-turbo
Co-Authored-By: jiabowen <jiabowen@uniontech.com>
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign liujianqiang-niu for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown

TAG Bot

TAG: 255.2-4deepin31
EXISTED: no
DISTRIBUTION: unstable

@deepin-community-ci-bot

Copy link
Copy Markdown

TAG Bot

New tag: 255.2-4deepin32
DISTRIBUTION: unstable
Suggest: synchronizing this PR through rebase #63

@deepin-community-ci-bot

Copy link
Copy Markdown

TAG Bot

New tag: 255.2-4deepin33
DISTRIBUTION: unstable
Suggest: synchronizing this PR through rebase #64

@deepin-community-ci-bot

Copy link
Copy Markdown

TAG Bot

New tag: 255.2-4deepin34
DISTRIBUTION: unstable
Suggest: synchronizing this PR through rebase #65

@deepin-community-ci-bot

Copy link
Copy Markdown

TAG Bot

New tag: 255.2-4deepin35
DISTRIBUTION: unstable
Suggest: synchronizing this PR through rebase #66

@deepin-community-ci-bot

Copy link
Copy Markdown

TAG Bot

New tag: 255.2-4deepin36
DISTRIBUTION: unstable
Suggest: synchronizing this PR through rebase #67

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants