Skip to content

fix(cve): CVE-2026-76163 - Always create the TKEY context - #14

Merged
Zeno-sole merged 17 commits into
masterfrom
fix-cve/CVE-2026-76163
Sep 20, 2026
Merged

Zeno-sole merged 17 commits into
masterfrom
fix-cve/CVE-2026-76163

Conversation

@deepin-ci-robot

@deepin-ci-robot deepin-ci-robot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

CVE: CVE-2026-76163 (high) - If BIND is loaded with a named.conf file that contains no global options block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit.
Upstream: isc-projects/bind9@4a48f9b73f

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-77692 (high) - 修复使用 SIG(0) 的 HTTPS 未认证崩溃漏洞
Upstream: https://github.com/isc-projects/bind9/commit/d1c25323509173e4d65785e1d1781de77bf461a6.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-19666 (high) - On a resolver configured to use dns64, if an applicable answer from the authoritative server is malformed in a specific way, the resolver named process will exit unexpectedly.
Upstream: isc-projects/bind9@9ddfd2e4da7374ab2f6eaa67cd48d99116a8f60e,https://github.com/isc-projects/bind9/commit/bc4a9ce4d3940f1c5f02f885253e7fbe201de7c4

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-81563 - 兼容性适配修改:将不存在的 dns_rdataset_cleanup 替换为已有的 dns_rdataset_disassociate

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-19941 (medium) - Require NSEC wildcard proofs from the same zone
Upstream: isc-projects/bind9@ac43c31

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-77119 (medium) - NSEC3 签名者边界检查漏洞,允许跨域 NSEC3 降级安全委派
Upstream: isc-projects/bind9@f76b344

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-75029 (medium) - In a query response, an attacker may send named multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly ...
Upstream: https://github.com/isc-projects/bind9/commit/905f6cc0a3f5347eb849b33fdbe4898e2445e47d.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-19668 - 兼容性适配修改:恢复 validator_cancel_finish 和 validate_answer_finish 的前向声明,修复 C11 标准下的隐式函数声明编译错误

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-19033 - 兼容性适配修改:删除已移除结构体字段 sincetsig 的残留引用

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b

CVE: CVE-2026-76163 (high) - If BIND is loaded with a named.conf file that contains no global options block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit.
Upstream: isc-projects/bind9@4a48f9b73f

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign zeno-sole for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions

Copy link
Copy Markdown

TAG Bot

TAG: 1%9.20.23-1_deb13u1deepin12
EXISTED: no
DISTRIBUTION: unstable

@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

/hold
因为该quilt包的上游版本号变更,详情见: deepin-community/infra-settings#134

deepin-ci-robot and others added 14 commits September 18, 2026 20:19
…g SIG(0)

CVE: CVE-2026-77692 (high) - 修复使用 SIG(0) 的 HTTPS 未认证崩溃漏洞
Upstream: https://github.com/isc-projects/bind9/commit/d1c25323509173e4d65785e1d1781de77bf461a6.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
… DNS64 filter64 path

CVE: CVE-2026-19666 (high) - On a resolver configured to use dns64, if an applicable answer from the authoritative server is malformed in a specific way, the resolver named process will exit unexpectedly.
Upstream: isc-projects/bind9@9ddfd2e4da7374ab2f6eaa67cd48d99116a8f60e,https://github.com/isc-projects/bind9/commit/bc4a9ce4d3940f1c5f02f885253e7fbe201de7c4

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…data lookups fail

CVE: CVE-2026-81563 (high) - A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources. If this happens repeatedly, resource exhaustion will eventually prevent the resolver from performing new recursive lookups.
Upstream: CVEProject/cvelistV5@3da381e

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-81563 - 兼容性适配修改:将不存在的 dns_rdataset_cleanup 替换为已有的 dns_rdataset_disassociate

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…the same zone

CVE: CVE-2026-19941 (medium) - Require NSEC wildcard proofs from the same zone
Upstream: isc-projects/bind9@ac43c31

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…C downgrade of secure delegati

CVE: CVE-2026-77119 (medium) - NSEC3 签名者边界检查漏洞,允许跨域 NSEC3 降级安全委派
Upstream: isc-projects/bind9@f76b344

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-75029 (medium) - In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increased memory usage of the negative cache and possibly ...
Upstream: https://github.com/isc-projects/bind9/commit/905f6cc0a3f5347eb849b33fdbe4898e2445e47d.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…ve CPU use validating crafted

CVE: CVE-2026-19668 (medium) - sec: usr: Prevent excessive CPU use validating crafted DNSSEC responses
Upstream: isc-projects/bind9@8d66075

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-19668 - 兼容性适配修改:恢复 validator_cancel_finish 和 validate_answer_finish 的前向声明,修复 C11 标准下的隐式函数声明编译错误

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-19033 (medium) - Remove support for sparse TSIG - RFC8945 mandates that zone transfers sign each message, but also requires implementations to support sparsely signed transfers for backward compatibility. This backward compatibility measure could be chained with other issues by on-path attackers to execute them with lower privileges.
Upstream: https://github.com/isc-projects/bind9/commit/fa351e24e2f97777a3087a9f91998e22cd336deb.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-19033 - 兼容性适配修改:删除已移除结构体字段 sincetsig 的残留引用

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
bind9 9.20.23 不提供 dns_name_empty()、DNS_RDATASET_FOREACH() 和
dns_rdataset_cleanup(),而回移的 upstream commit ac43c316 在
lib/dns/validator.c 中引用了它们,导致 -Werror=implicit-function-declaration
编译失败(validator.c:2565/2586)以及 cleanup 标签解析错误。

刷新 CVE-2026-19941.patch,改用本版本已有的等价实现:
- dns_name_empty(x)      -> dns_name_countlabels(x) == 0
- DNS_RDATASET_FOREACH() -> 显式 dns_rdataset_first()/next() 循环
- dns_rdataset_cleanup() -> dns_rdataset_isassociated() + disassociate()
9.20.23 的 dns_nsec3_noexistnodata() 仍然带有 setclosest 参数(15 个参数),
而回移的 upstream commit ac43c316 按新签名只传了 14 个,导致
-Werror=implicit-function-declaration 之外还报 too few arguments。

在 checkwildcard() 的 NSEC3 分支调用中补一个 NULL 作为 setclosest。
9.20.23 的 isc/util.h 还没有 CLEANUP() 宏,回移的 upstream commit
fa351e24 在 xfrin_recv_done() 中新增了 CLEANUP(DNS_R_EXPECTEDTSIG),
导致 -Werror=implicit-function-declaration。

展开为等价的 result = DNS_R_EXPECTEDTSIG; goto cleanup;
@Zeno-sole

Copy link
Copy Markdown
Contributor

/integrate

@github-actions

Copy link
Copy Markdown

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#4573
PrNumber: 4573
PrBranch: auto-integration-35486089280

Several adaptations in this backport set did not preserve upstream behaviour.
Fix the ones that change what ships:

- CVE-2026-77119: only the label-depth check from upstream patch 2/3 of
  f76b3440 was backported; the relevance gate was dropped.  The depth check
  is a necessary but not sufficient condition, so a validly signed NSEC3
  owned by an unrelated sibling zone (same depth as the queried name's
  parent) still passed and could downgrade a secure delegation.  Add the
  missing dns_name_getlabelsequence()/dns_name_issubdomain() gate.
- CVE-2026-75029: upstream relies on newrdata() resetting a recycled
  dns_rdata_t, which 9.20.23 does not do.  Releasing the skipped duplicate
  rdata as-is handed a populated rdata to the next
  dns_message_gettemprdata(), tripping the DNS_RDATA_INITIALIZED requirement
  in dns_rdata_fromwire() and aborting named on any message that repeats a
  singleton record and then carries another record.  Reset the rdata before
  returning it to the pool, register tests/dns/message_test in Makefile.am
  (9.20 builds unit tests with autotools, not meson) and adapt the test to
  9.20, which has no isc/lib.h, dns/lib.h or isc_g_mctx.
- CVE-2026-81563: dns_rdataset_cleanup() does not exist in 9.20.23; its
  replacement must keep the dns_rdataset_isassociated() guard, because
  dns_rdataset_disassociate() requires an associated rdataset.
- CVE-2026-19668: restore the per-DS quota charging from upstream patch 3/4
  (consume_validation() plus over_max_validations()) and the
  validation_attempts increment for a DS that did match.
- CVE-2026-19941 / CVE-2026-77692: the new system tests used 9.21+ harness
  APIs (jinja includes, isctest.mark.with_ecdsa_deterministic,
  isctest.mark.with_libnghttp2) that do not exist in 9.20, so they could not
  run at all.  Spell the options out, use the existing
  isctest.mark.with_algorithm() helper, and gate the DoH test on libnghttp2
  through prereq.sh, the 9.20 way.

Verified: all 20 patches apply cleanly to a pristine tree, a full
configure && make succeeds, tests/dns/message_test builds and passes, both
rewritten named.conf.j2 render and pass named-checkconf, and the new NSEC3
gate rejects the sibling-zone proof while still accepting the genuine parent
and grandparent proofs.

Log: completed and corrected the CVE backports, including an NSEC3 relevance
gate and a parse-path abort introduced by the message.c backport

Influence:
1. Validate a zone whose parent DS answer carries a sibling-signed NSEC3
2. Parse queries and responses that repeat a singleton record and then carry
   more records (named must not abort)
3. Run tests/dns/message_test and the nsec_wildcard_wrong_zone and
   sig0_https system tests
4. Re-check DNSSEC validation of normal NXDOMAIN, wildcard and NODATA answers
5. Confirm named-checkconf accepts the rewritten system test configurations

fix(cve): 补全 9.20.23 安全更新中的 CVE 回移

本次回移中有若干适配没有保持上游行为,修正其中会影响出厂包的部分:

- CVE-2026-77119:只回移了上游 f76b3440 patch 2/3 的标签深度判断,漏掉了
  相关性判断。深度判断只是必要条件而非充分条件,因此一个由无关同级 zone
  合法签名、深度与所查名字父域相同的 NSEC3 仍会通过,可将安全委派降级。
  补上缺失的 dns_name_getlabelsequence()/dns_name_issubdomain() 判断。
- CVE-2026-75029:上游依赖 newrdata() 会重置回收的 dns_rdata_t,而 9.20.23
  不会。被跳过的重复 rdata 未重置就归还池中,下次
  dns_message_gettemprdata() 会拿到已填充的 rdata,触发 dns_rdata_fromwire()
  中的 DNS_RDATA_INITIALIZED 断言,导致任何"重复单例记录后还有其他记录"的
  报文使 named 中止。归还池前先重置 rdata;同时把 tests/dns/message_test 注册
  进 Makefile.am(9.20 单测用 autotools 而非 meson),并适配 9.20(无
  isc/lib.h、dns/lib.h、isc_g_mctx)。
- CVE-2026-81563:9.20.23 没有 dns_rdataset_cleanup(),替代实现必须保留
  dns_rdataset_isassociated() 保护,因为 dns_rdataset_disassociate() 要求
  rdataset 已关联。
- CVE-2026-19668:恢复上游 patch 3/4 的 per-DS 配额计费(consume_validation()
  与 over_max_validations())以及"DS 确实匹配到 DNSKEY"时的 validation_attempts
  计数。
- CVE-2026-19941 / CVE-2026-77692:新增 system test 使用了 9.20 不存在的
  9.21+ 测试框架 API(jinja include、isctest.mark.with_ecdsa_deterministic、
  isctest.mark.with_libnghttp2),完全无法运行。改为展开配置项、使用已有的
  isctest.mark.with_algorithm(),并用 9.20 的 prereq.sh 方式限制 libnghttp2。

已验证:20 个补丁在干净树上全部应用成功,完整 configure && make 通过,
tests/dns/message_test 编译并通过,两个重写的 named.conf.j2 可渲染且通过
named-checkconf,新的 NSEC3 判断会拒绝同级 zone 的证明,同时仍接受真实父域与
祖父域的证明。

Log: 补全并修正 CVE 回移,包括 NSEC3 相关性判断与 message.c 回移引入的解析中止

Influence:
1. 验证父域 DS 应答中携带同级 zone 签名的 NSEC3 的域
2. 解析"重复单例记录后还有其他记录"的查询与应答(named 不得中止)
3. 运行 tests/dns/message_test 以及 nsec_wildcard_wrong_zone、sig0_https 测试
4. 回归 DNSSEC 对正常 NXDOMAIN、通配符、NODATA 应答的验证
5. 确认 named-checkconf 接受重写后的 system test 配置

repo: bind9 #fix-cve/CVE-2026-76163
@Zeno-sole

Copy link
Copy Markdown
Contributor

/integrate

The backport of CVE-2026-19668 kept the DS-by-DNSKEY work bound from
upstream 8d660756 patch 3/4, but dropped the other half of the same
security merge, upstream patch 2/4 (4927b46245, "Make the exhausted
DNSSEC validation quota terminal").  The validator produces ISC_R_QUOTA
once the per-fetch validation quota is exhausted, yet nothing consumed it
terminally:

- fetch_callback_dnskey() and both switches in fetch_callback_ds() fell
  through to their default arm and relabelled ISC_R_QUOTA as
  DNS_R_BROKENCHAIN, losing the distinction upstream relies on.
- validated() in lib/dns/resolver.c only gave up on DNS_R_BROKENCHAIN, so
  an exhausted quota fell into fctx_try() and the fetch was retried.
  Retrying does more validation work against the same, already exhausted
  quota, which is exactly the CPU use this CVE is about.

Restore the missing upstream hunks: let the fetch callbacks pass
ISC_R_CANCELED, ISC_R_SHUTTINGDOWN and ISC_R_QUOTA through unchanged, and
treat those results, like DNS_R_BROKENCHAIN, as terminal in validated()
so the fetch is not retried.

The additions match the released 9.20 branch (v9.20.29) for
fetch_callback_dnskey() and both fetch_callback_ds() arms; in
validated() the released 9.20 branch already carries the upstream switch
form, so the equivalent condition is expressed in the if/else-if chain
this version uses.

Log: restored the terminal handling of an exhausted DNSSEC validation quota

Influence:
1. Validate a zone whose parent DS RRset is flooded with mismatched DS
   records and confirm the query stops instead of retrying the fetch
2. Check named logs "maximum number of validations exceeded" rather than
   "broken trust chain" when the per-fetch quota is reached
3. Re-run the dnssec system test to confirm ordinary validation is
   unaffected
4. Confirm a canceled or shutting-down validation still aborts promptly
5. Verify the full patch series applies to a pristine 9.20.23 tree and the
   package builds

fix(cve): CVE-2026-19668 - 让耗尽的验证配额成为终止性错误

CVE-2026-19668 的回移保留了上游 8d660756 patch 3/4 的 DS×DNSKEY 工作量
上界,却漏掉了同一次安全合并里的另一半,即上游 patch 2/4
(4927b46245,"Make the exhausted DNSSEC validation quota terminal")。
验证器在 per-fetch 验证配额耗尽后会产出 ISC_R_QUOTA,但没有任何地方
把它当作终止性结果:

- fetch_callback_dnskey() 和 fetch_callback_ds() 的两个 switch 都会落到
  default 分支,把 ISC_R_QUOTA 改写成 DNS_R_BROKENCHAIN,丢掉了上游
  依赖的这一区分。
- lib/dns/resolver.c 的 validated() 只对 DNS_R_BROKENCHAIN 放弃重试,
  于是配额耗尽会落入 fctx_try() 重试该次 fetch。重试会对同一份已经耗尽
  的配额做更多验证工作,而这正是本 CVE 要防的 CPU 消耗。

补回上游遗漏的 hunk:让两个 fetch 回调把 ISC_R_CANCELED、
ISC_R_SHUTTINGDOWN、ISC_R_QUOTA 原样传出,并在 validated() 里把这三个
结果与 DNS_R_BROKENCHAIN 一并视为终止,不再重试 fetch。

新增内容与已发布的 9.20 分支(v9.20.29)的 fetch_callback_dnskey() 及
fetch_callback_ds() 两个分支逐字一致;validated() 在 9.20 分支上已经是
上游的 switch 写法,本版本用的是 if/else-if 链,故以等价条件表达。

Log: 恢复耗尽的 DNSSEC 验证配额应终止而非重试的处理

Influence:
1. 验证父域 DS 记录集被大量不匹配 DS 灌水的域,确认查询会停止而不是
   反复重试 fetch
2. 确认达到 per-fetch 配额时 named 日志显示 "maximum number of
   validations exceeded" 而非 "broken trust chain"
3. 重跑 dnssec system test,确认正常验证流程没有回归
4. 确认被取消或正在关闭的验证仍能立即中止
5. 确认整条补丁链能在干净的 9.20.23 树上应用且包能构建

repo: bind9 #fix-cve/CVE-2026-76163
@Zeno-sole

Copy link
Copy Markdown
Contributor

/integrate

@Zeno-sole

Copy link
Copy Markdown
Contributor

/test ai-review

@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

deepin pr auto review

AI 代码审查报告

项目:deepin-community/bind9 (PR #14)
分支:fix-cve/CVE-2026-76163 → master
提交:d489fa8 (fix(cve): CVE-2026-76163 - Always create the TKEY context)
平台:GitHub
审查时间:2026-09-20


总体评价

总体评分:99 / 100
总体结论:代码审查通过
评价原因:本次 PR 为 bind9 9.20.23 安全更新,backport 上游 9 个 CVE 修复(3 高危 + 6 中危),涉及 TKEY 断言失败、SIG(0) HTTPS 崩溃、DNS64 内存泄漏、NSEC/NSEC3 跨域验证绕过、DNSSEC 验证配额 DoS、单例记录重复内存膨胀、SVCB additional-data 资源泄漏、sparse TSIG 移除等。所有补丁按 series 顺序整体应用验证通过,deepin 兼容性适配(CLEANUP 宏展开、dns_rdataset_cleanup→isassociated+disassociate、dns_rdataset_reset 补齐、前向声明恢复)均正确且注释充分。未发现本次 PR 新引入的安全漏洞,安全扫描器 15 个 RCE 发现经核实均为注释/变量名关键字误报且不在修改 hunk 内,OCR 审查 0 问题。


修改文件清单

文件 类型 说明
debian/changelog 打包元数据 新增 1:9.20.23-1~deb13u1deepin12 版本条目
debian/patches/CVE-2026-76163.patch 安全补丁 TKEY 上下文始终创建(high)
debian/patches/CVE-2026-77692.patch 安全补丁 SIG(0) HTTPS 未认证崩溃(high)
debian/patches/CVE-2026-19666.patch 安全补丁 DNS64 noqname 别名清理(high)
debian/patches/CVE-2026-81563.patch 安全补丁 SVCB additional-data rdataset 释放(high)
debian/patches/CVE-2026-19941.patch 安全补丁 NSEC 通配符证明同区校验(medium)
debian/patches/CVE-2026-77119.patch 安全补丁 NSEC3 签名者区 enclosure 校验(medium)
debian/patches/CVE-2026-75029.patch 安全补丁 跳过重复单例记录(medium)
debian/patches/CVE-2026-19668.patch 安全补丁 DNSSEC 验证配额终态化(medium)
debian/patches/CVE-2026-19033.patch 安全补丁 移除 sparse TSIG 支持(medium)
debian/patches/series 补丁索引 追加 9 个新补丁条目

维度1:语法逻辑(25/25)✓ 语法正确,逻辑清晰

  1. 补丁应用验证:9 个新 CVE 补丁 + 11 个既有补丁共 20 个,按 debian/patches/series 顺序整体 git apply 全部成功,无 hunk 失败、无上下文漂移。
  2. CVE-2026-76163(tkeyconf.c named_tkeyctx_fromconfig):将 tkey-gssapi-credential 与 tkey-gssapi-keytab 两处 cfg_map_get 完整包裹于 if (options != NULL) 内,server.c 中 TKEY 创建移出 if (options != NULL) 守卫并由 tkeyconf 内部处理 NULL options,逻辑自洽,消除了无 global options 块时的断言失败路径。
  3. CVE-2026-19033(xfrin.c):移除 tsigctx/sincetsig 字段及相关 dst_context_destroy/取回逻辑,将 dns_message_checksig 前移至状态化响应处理之前并新增 DNS_R_EXPECTEDTSIG 校验(deepin 将 CLEANUP(DNS_R_EXPECTEDTSIG) 展开为 result = DNS_R_EXPECTEDTSIG; goto cleanup;),资源所有权转由 dns_message 自身管理,无泄漏。
  4. CVE-2026-19941(validator.c checkwildcard):重构为 switch 结构,NSEC 分支前置 valid_nsec_signer 同区签名校验,continue 语义正确(for 循环跳至增量表达式 val_rdataset_next),trdataset 末尾 dns_rdataset_isassociated 清理保留;validate_nx 调用点以 dns_name_countlabels(nseczone) > 0 守卫,NSEC3 路径 findnsec3proofs 内 zonename 空时提前返回,无验证回退风险。
  5. CVE-2026-19668(validator.c validate_dnskey_dsset):移除 dns_rdata_reset(&dsrdata) 安全——该处 dsrdata 声明为 DNS_RDATA_INIT(validator.c:2192)且单次使用无循环复用;resume_answer_with_key_done 将 ISC_R_QUOTA/CANCELED/SHUTTINGDOWN 由 dns_validator_cancel 改为 validate_answer_finish 终态处理,与 upstream 4927b46245 意图一致,避免配额耗尽后重试。
  6. CVE-2026-75029(message.c getsection):重复单例记录在 !best_effort 路径执行 dns_rdata_reset + dns_message_puttemprdata 归还池,并以 if (rdata != NULL) 守卫后续 ISC_LIST_APPEND,deepin 补齐的 dns_rdata_reset 修复了 9.20.23 newrdata() 不重置回收 rdata 的问题。
  7. CVE-2026-81563(svcb_64.c generic_additionaldata_in_svcb):将 RETERR(add(...)) 替换为显式 result = add(...) + dns_rdataset_isassociated 守卫的 dns_rdataset_disassociate,正确替代 9.20.23 缺失的 dns_rdataset_cleanup,错误路径无悬空释放。
  8. CVE-2026-77692(http.c/netmgr.c):http_session_active→isc__nm_httpsession_active 改公开并新增 session->handle != NULL 判定,get_proxy_handle 增加活跃性守卫,消除 SIG(0) 校验后连接关闭的空指针解引用崩溃。
  9. CVE-2026-19666(query.c query_addanswer):query_filter64 后置 qctx->noqname = NULL,清除 dns64 过滤路径的 noqname 别名悬空引用,一行修复精准。

维度2:代码质量(24/25)✓ 代码结构清晰,注释完整

  1. 所有 9 个新补丁均含完整 DEP-3 头(Description / Author / Origin / Bug / Last-Update),[deepin] 适配说明详尽(如 CVE-2026-81563 说明 dns_rdataset_cleanup 不存在的原因与替代方案、CVE-2026-75029 说明 newrdata() 不重置的根因),可维护性优秀。
  2. debian/changelog 采用多维护者条目([deepin-ci-robot]、[lichenggang]),版本号 1:9.20.23-1~deb13u1deepin12 格式规范,时间戳 Fri, 18 Sep 2026 20:09:05 +0800 符合 RFC 2822。
  3. 新增辅助函数 valid_nsec_signer、find_sigrdataset 抽象合理,消除了 validate_authority 中的内联查找重复代码,单一职责清晰。
  4. 测试覆盖充分:每个 CVE 均配套系统测试/单元测试(CVE-2026-75029 新增 tests/dns/message_test.c 并注册到 Makefile.am,CVE-2026-19941/77692 配套 nsec_wildcard_wrong_zone/sig0_https 测试套件,CVE-2026-19668 配套 delegationtrap 复现器)。
  5. 轻微问题(-1):debian/changelog 中部分上游 commit URL 被换行拆分(如 "https://github.com/isc-\n projects/bind9/commit/..."),主机名 isc-projects 被截断跨行,直接复制会得到断裂链接,建议长 URL 单独成行或使用续行符明确标注。

维度3:代码性能(20/20)✓ 性能良好,资源使用合理

  1. CVE-2026-19668 主动增强 DoS 防护:新增 DS×DNSKEY 组合上限(DS_DNSKEY_COMBINATIONS_PER_VALIDATION = 2)、validate_dnskey_dsset 中 matchds_attempts 计数、无匹配 DS 路径 consume_validation/over_max_validations 配额扣减,有效限制 KeyTrap 算法复杂度攻击的 CPU 放大。
  2. CVE-2026-75029 防止负缓存内存膨胀:跳过重复单例记录避免 RDATA 集合无限追加,降低攻击者构造重复 SOA 记录导致的内存占用。
  3. CVE-2026-19668 validated() 将 ISC_R_QUOTA 列为终态结果不再 fctx_try 重试,避免配额耗尽后无效重试造成的额外 CPU 开销。
  4. CVE-2026-19033 移除 sparse TSIG 簿记(sincetsig 计数、tsigctx 取回/销毁),简化 xfrin 热路径,减少每消息的状态管理开销。
  5. 其余补丁为正确性/安全修复,无算法复杂度退化、无频繁系统调用、无资源泄漏引入。

维度4:代码安全(30/30)✓ 存在0个安全漏洞

漏洞对比统计:新增漏洞 0 个,减少漏洞 0 个,持平 0 个

本次 PR 为安全补丁 backport,本身修复 9 个上游 CVE(3 high + 6 medium),未引入任何新的安全漏洞。安全扫描器(security_scanner.py)对 10 个修改源文件报告 15 个 RCE 发现,经逐一核实均为误报:标记行(如 validator.c:257 注释 "Validator 'val' is finished"、validator.c:3277 文档注释 "ISC_R_COMPLETE"、resolver.c:381-383 等)均为代码注释或变量名关键字匹配命中,并非真实命令执行/远程代码执行,且全部位于本次 PR 未修改的既有代码区域。OCR 专业代码审查工具审查结果:0 comments,"Looks good to me"。

安全扫描发现核实(均为误报,不计入漏洞):

安全漏洞1:security_scanner.py 报告 validator.c:257 为 critical RCE(CWE-78)。经核实该行为注释 "Validator 'val' is finished; send the completion event...",关键字 "execute" 命中误报,非真实命令执行,且不在本次修改 hunk 内。——非常重要

安全漏洞2:security_scanner.py 报告 validator.c:3277 为 critical RCE(CWE-78)。经核实该行为文档注释 "ISC_R_COMPLETE a result has been determined",关键字命中误报,非真实漏洞,不在本次修改 hunk 内。——非常重要

安全漏洞3:security_scanner.py 报告 resolver.c:381-383 为 critical RCE(CWE-78)。经核实为既有 DNS 解析器代码,非命令执行,不在本次修改 hunk 内。——非常重要

安全漏洞4-15:security_scanner.py 报告 server.c/tkeyconf.c/http.c/netmgr.c/message.c/svcb_64.c/query.c 等共 12 个 critical/high 发现,经核实均为注释、日志格式化字符串或 DNS 协议处理函数名关键字匹配误报(如 "command"、"execute"、"system" 在 DNS 上下文中的合法使用),无真实 RCE/命令注入,均不在本次修改 hunk 内。——非常重要

本次 PR 实际安全增强(漏洞修复,非新引入):

  1. CVE-2026-76163(high):消除无 global options 配置下 TKEY 查询的断言失败崩溃。
  2. CVE-2026-77692(high):消除 SIG(0) HTTPS 场景连接关闭后的空指针解引用崩溃。
  3. CVE-2026-19666(high):修复 DNS64 过滤路径 noqname 别名悬空引用导致的意外退出。
  4. CVE-2026-81563(high):修复 SVCB additional-data 回调失败时 rdataset 未释放的资源泄漏。
  5. CVE-2026-19941(medium):要求 NSEC 通配符证明来自同一区域,防跨区伪造。
  6. CVE-2026-77119(medium):NSEC3 签名者区 enclosure 校验,防跨域 NSEC3 降级安全委派。
  7. CVE-2026-75029(medium):跳过重复单例记录,防负缓存内存膨胀 DoS。
  8. CVE-2026-19668(medium):DNSSEC 验证配额终态化,防 KeyTrap CPU 耗尽 DoS。
  9. CVE-2026-19033(medium):移除 sparse TSIG 支持,简化验证逻辑减少攻击面。

改进建议

  1. debian/changelog 中长 URL(如 https://github.com/isc-projects/bind9/commit/d1c25323509173e4d65785e1d1781de77bf461a6.patch)建议单独成行或确保续行不断裂主机名,便于追溯。
  2. CVE-2026-19668 补丁较大(727 行),建议在 debian/patches/series 注释中标注其依赖的上游 patch 序列(2/4、3/4),便于后续维护者理解补丁组成。

审查结论

本次 PR 质量优秀,9 个 CVE 补丁 backport 准确,deepin 9.20.23 兼容性适配均有详尽注释说明根因与替代方案,所有补丁按 series 顺序整体应用通过,配套测试覆盖充分。未引入新的安全漏洞(扫描器 15 个发现经核实全部为关键字误报且不在修改范围内,OCR 0 问题)。代码审查通过,建议合并。

@Zeno-sole
Zeno-sole merged commit e798a66 into master Sep 20, 2026
5 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants