| Summary: | Dnsmasq: multiple CVEs in Widely Used Dnsmasq Network Software ** Severity urgent ** | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] Security - Recipe Upgrade | Reporter: | Sona Sarmadi <sona.sarmadi> |
| Component: | security | Assignee: | Joe Slater <joe.slater> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | critical | ||
| Priority: | Medium | CC: | akuster, bluelightning, randy.macleod, stephano |
| Version: | unspecified | ||
| Target Milestone: | 2.3.4 | ||
| Hardware: | Other | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Sona Sarmadi
2017-10-04 06:21:21 UTC
FWIW I have sent an upgrade for meta-networking master to 2.78 (in master-next, not yet merged into master): https://patchwork.openembedded.org/patch/144640/ That version includes fixes for the following CVEs (from dnsmasq's own changelog): CVE-2017-13704 CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496 Are you sure you have the CVE numbers correct? CVE-2017-14497 appears to be for the kernel and not dnsmasq. To update the status - my patch was merged into master (and rocko when it branched), but we are still missing fixes for pyro and possibly morty / earlier. I am not currently working on those - is anyone else? backport to pyro and morty stable/*. pending merge to real branch need to build, test and merge to stable branches Joe, can you build, test and if all goes well, send backport patches for pyro and morty to help out Armin. Looking into using 2.78 -> 2.76 backport. CVE-2017-13704 is not relevant to 2.76 and is fixed in 2.78. Add a comment to see if Joe gets an email. Patch sent for meta-networking/morty. patches submitted to maintainer for inclusion in stable branches. Still marked as new in patchworks: https://patchwork.openembedded.org/patch/150498/ |