Retour aux alertes CVE
CVE-2026-10657 LOW CVSS 3.7

CVE-2026-10657 — LOW

Publiée 2 months ago Fiche NVD officielle

Qu'est-ce que c'est ?

Zephyr's DNS resolver detects mDNS (.local) queries in dns_resolve_name_internal() (subsys/net/lib/dns/resolve.c) with memcmp(strrchr(query, '.'), ".local", 7), which always reads a fixed 7 bytes from the suffix pointer. When the resolved hostname's final label is shorter than 7 bytes (e.g. names ending in .org, .com, .net, .io, or a trailing dot), the comparison reads 1-2 bytes past the string's NUL terminator. The hostname (query) is the caller-supplied name passed through the standard getaddrinfo()/dns_get_addr_info()/dns_resolve_name() path and is influenceable by operators or remote inputs (server names from configuration, parsed URLs, or app-facing interfaces). On a tightly-sized buffer with no slack (for example a userspace getaddrinfo call where the hostname is copied with k_usermode_string_alloc_copy to exactly strlen+1 bytes), the over-read crosses the allocation boundary; if that boundary is unmapped (guard page, memory-domain boundary under MPU, or an address sanitizer) the over-read faults, causing a denial of service. The over-read bytes are never returned, so there is no information disclosure. The flaw is compiled only when CONFIG_MDNS_RESOLVER is enabled, exists since v1.10.0, and is fixed by replacing the fixed-length memcmp with a NUL-safe strcmp(ptr, ".local").

Technologies affectées

Non précisé par la fiche NVD.

Recommandation

Vérifie la disponibilité d'un correctif pour la technologie concernée et applique-le dès que possible. Consulte la fiche NVD pour les références officielles du fournisseur.

Exploits publics connus (0)

Aucun proof-of-concept public trouvé sur GitHub à ce jour. Ça peut changer : les PoC sont souvent publiés plusieurs jours ou semaines après la divulgation.