2
0
mirror of https://github.com/xcat2/xcat-dep.git synced 2026-09-30 14:55:17 +00:00

fix(xcat-dep): the riscv64 Net::DNS carries CVE-2026-64193 and CVE-2026-64194

perl-Net-DNS built Net::DNS 1.47 without patches. That release decodes
the EDNS EXTENDED-ERROR text with a string eval (CVE-2026-64193) and
follows compression pointer chains of any depth (CVE-2026-64194).
Net::DNS 1.56 fixes both, and 1.57 also stops an unbounded recursion on
a misplaced TSIG.

Build Net::DNS 1.57. The tarball, the spec, the Buildnote and the
riscv64 manifest pin move together. The build requirements of 1.57 are
the same as those of 1.47.

t/net_dns_rr_types.t decodes a reply with a 200-pointer chain and fails
on 1.47.

Signed-off-by: Daniel Hilst <392820+dhilst@users.noreply.github.com>
This commit is contained in:
Daniel Hilst
2026-09-29 08:46:22 -03:00
parent 398f3703f3
commit e125f6f79f
6 changed files with 14 additions and 8 deletions
+4 -3
View File
@@ -489,9 +489,10 @@ Deliberately not built for riscv64:
Test::XML) are EPEL-only as well, so it can neither be built nor installed without EPEL;
xCAT uses it for HP blade and VirtualBox support only.
perl-Net-DNS is built from `perl-Net-DNS/Net-DNS.spec` at 1.47, the release EPEL 10 ships,
so the riscv64 repo carries the same resource records as the EPEL-fed repos. xCAT needs the
KEY record, which release 0.80 left to the separate Net::DNS::SEC distribution. This spec
perl-Net-DNS is built from `perl-Net-DNS/Net-DNS.spec` at 1.57. xCAT needs the KEY record,
which release 0.80 left to the separate Net::DNS::SEC distribution. 1.57 is newer than the
1.47 that EPEL 10 ships, because 1.56 and 1.57 fix CVE-2026-64193, CVE-2026-64194 and an
unbounded recursion on TSIG. This spec
does not take the EPEL-only perl(Net::LibIDN2) BuildRequires of the EPEL package:
Net::DNS treats Net::LibIDN2 as optional and uses it for internationalised names only.
+1 -1
View File
@@ -180,7 +180,7 @@ perl-Crypt-Rijndael=1.13
perl-Digest-SHA1=2.13
perl-Expect=1.35
perl-Mail-Sender=0.903
perl-Net-DNS=1.47
perl-Net-DNS=1.57
perl-Net-IP=1.26
perl-Path-Class=0.37
+1 -1
View File
@@ -1,6 +1,6 @@
How to build the perl-Net-DNS
1. cp the Net-DNS-1.47.tar.gz to the rpmbuild/SOURCES/
1. cp the Net-DNS-1.57.tar.gz to the rpmbuild/SOURCES/
2. cp the Net-DNS.spec to the rpmbuild/SPECS/
3. cd rpmbuild/SPECS/
4. rpmbuild -bb Net-DNS.spec (Net::DNS is pure perl, so the rpm is noarch and one
Binary file not shown.
Binary file not shown.
+8 -3
View File
@@ -2,7 +2,7 @@
# - Net::DNS -
# This spec file was automatically generated by cpan2rpm [ver: 2.028]
# The following arguments were used:
# ./Net-DNS-1.47.tar.gz
# ./Net-DNS-1.57.tar.gz
# For more information on cpan2rpm please visit: http://perl.arix.com/
#
@@ -13,7 +13,7 @@
name: perl-Net-DNS
summary: Net-DNS - Perl DNS resolver module
version: 1.47
version: 1.57
release: 1
vendor: Olaf Kolkman <olaf@net-dns.org>
packager: Arix International <cpan2rpm@arix.com>
@@ -23,7 +23,7 @@ url: http://www.cpan.org
buildroot: %{_tmppath}/%{name}-%{version}-%(id -u -n)
buildarch: noarch
prefix: %(echo %{_prefix})
source: Net-DNS-1.47.tar.gz
source: Net-DNS-1.57.tar.gz
# cpan2rpm specs carry no BuildRequires; an EL10 buildroot has neither perl nor make, and
# perl-generators is what makes rpm compute the perl(...) Requires.
@@ -146,6 +146,11 @@ find %{buildroot}%{_prefix} \
%defattr(-,root,root)
%changelog
* Tue Sep 29 2026 xCAT build - 1.57-1
- Net::DNS 1.57. 1.47 carries CVE-2026-64193 (code injection via EDNS
EXTENDED-ERROR) and CVE-2026-64194 (deep compression pointer chains),
fixed in 1.56, and unbounded recursion on a misplaced TSIG, fixed in 1.57.
* Sat Sep 05 2026 xCAT build - 1.47-1
- Net::DNS 1.47. Release 0.80 leaves the DNSSEC records to Net::DNS::SEC, so
Net::DNS::RR->new("<key>. IN KEY ...") dies and xCAT makedns fails. 1.47 is