Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
188 changes: 188 additions & 0 deletions SPECS/coredns/CVE-2026-56852.patch
Original file line number Diff line number Diff line change
@@ -0,0 +1,188 @@
From 4c6ec1e3b454c90cfe7aff9021b22ed5102e990f Mon Sep 17 00:00:00 2001
From: Damien Neil <dneil@google.com>
Date: Tue, 14 Apr 2026 21:46:24 -0400
Subject: [PATCH] unicode/norm: avoid infinite loop on invalid input

Invalid characters are given a Properties with a size of 0.

The nextComposed function can enter an infinite loop when
encountering an invalid character, since it advances
its input by the (possibly 0) character size.

Rather than finding every place which might assume characters
have a non-zero size, change compInfo to return a size-1
Properties for invalid characters and use the property flags
to record validity.

Fixes golang/go#80142

Change-Id: Ie0791faefeddc1e8f671b0ed73f29e906a6a6964
Reviewed-on: https://go-review.googlesource.com/c/text/+/794100
LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Auto-Submit: Damien Neil <dneil@google.com>
Reviewed-by: Neal Patel <neal@golang.org>
Reviewed-by: Neal Patel <nealpatel@google.com>
Signed-off-by: Azure Linux Security Servicing Account <azurelinux-security@microsoft.com>
Upstream-reference: https://github.com/golang/text/commit/5ae8e578e495731553eddba11b2d0e86c91a00ce.patch
---
.../x/text/unicode/norm/forminfo.go | 9 ++++++++-
vendor/golang.org/x/text/unicode/norm/iter.go | 8 ++------
.../x/text/unicode/norm/normalize.go | 20 +++++++++----------
3 files changed, 20 insertions(+), 17 deletions(-)

diff --git a/vendor/golang.org/x/text/unicode/norm/forminfo.go b/vendor/golang.org/x/text/unicode/norm/forminfo.go
index 487335d..6596a6b 100644
--- a/vendor/golang.org/x/text/unicode/norm/forminfo.go
+++ b/vendor/golang.org/x/text/unicode/norm/forminfo.go
@@ -118,8 +118,12 @@ func (p Properties) BoundaryAfter() bool {
//
// When all 4 bits are zero, the character is inert, meaning it is never
// influenced by normalization.
+//
+// We set flags to 0x80 (high bit 7 unused in quick check data) to indicate an invalid rune.
type qcInfo uint8

+func (p Properties) isInvalid() bool { return p.flags == 0x80 }
+
func (p Properties) isYesC() bool { return p.flags&0x10 == 0 }
func (p Properties) isYesD() bool { return p.flags&0x4 == 0 }

@@ -241,6 +245,9 @@ func (f Form) PropertiesString(s string) Properties {
// to a Properties. See the comment at the top of the file
// for more information on the format.
func compInfo(v uint16, sz int) Properties {
+ if sz == 0 {
+ return Properties{flags: 0x80, size: 1}
+ }
if v == 0 {
return Properties{size: uint8(sz)}
} else if v >= 0x8000 {
@@ -248,7 +255,7 @@ func compInfo(v uint16, sz int) Properties {
size: uint8(sz),
ccc: uint8(v),
tccc: uint8(v),
- flags: qcInfo(v >> 8),
+ flags: qcInfo(v>>8) & 0x3f,
}
if p.ccc > 0 || p.combinesBackward() {
p.nLead = uint8(p.flags & 0x3)
diff --git a/vendor/golang.org/x/text/unicode/norm/iter.go b/vendor/golang.org/x/text/unicode/norm/iter.go
index 417c6b2..3cc0592 100644
--- a/vendor/golang.org/x/text/unicode/norm/iter.go
+++ b/vendor/golang.org/x/text/unicode/norm/iter.go
@@ -376,16 +376,12 @@ func nextComposed(i *Iter) []byte {
goto doNorm
}
prevCC = i.info.tccc
- sz := int(i.info.size)
- if sz == 0 {
- sz = 1 // illegal rune: copy byte-by-byte
- }
- p := outp + sz
+ p := outp + int(i.info.size)
if p > len(i.buf) {
break
}
outp = p
- i.p += sz
+ i.p += int(i.info.size)
if i.p >= i.rb.nsrc {
i.setDone()
break
diff --git a/vendor/golang.org/x/text/unicode/norm/normalize.go b/vendor/golang.org/x/text/unicode/norm/normalize.go
index 4747ad0..60b1511 100644
--- a/vendor/golang.org/x/text/unicode/norm/normalize.go
+++ b/vendor/golang.org/x/text/unicode/norm/normalize.go
@@ -148,7 +148,7 @@ func (f Form) IsNormalString(s string) bool {
// patched buffer and whether the decomposition is still in progress.
func patchTail(rb *reorderBuffer) bool {
info, p := lastRuneStart(&rb.f, rb.out)
- if p == -1 || info.size == 0 {
+ if p == -1 || info.isInvalid() {
return true
}
end := p + int(info.size)
@@ -225,7 +225,7 @@ func doAppend(rb *reorderBuffer, out []byte, p int) []byte {
}
fd := &rb.f
if doMerge {
- var info Properties
+ info := Properties{flags: 0x80, size: 1} // invalid rune
if p < n {
info = fd.info(src, p)
if !info.BoundaryBefore() || info.nLeadingNonStarters() > 0 {
@@ -235,7 +235,7 @@ func doAppend(rb *reorderBuffer, out []byte, p int) []byte {
p = decomposeSegment(rb, p, true)
}
}
- if info.size == 0 {
+ if info.isInvalid() {
rb.doFlush()
// Append incomplete UTF-8 encoding.
return src.appendSlice(rb.out, p, n)
@@ -314,7 +314,7 @@ func (f *formInfo) quickSpan(src input, i, end int, atEOF bool) (n int, ok bool)
continue
}
info := f.info(src, i)
- if info.size == 0 {
+ if info.isInvalid() {
if atEOF {
// include incomplete runes
return n, true
@@ -379,7 +379,7 @@ func (f Form) firstBoundary(src input, nsrc int) int {
// CGJ insertion points correctly. Luckily it doesn't have to.
for {
info := fd.info(src, i)
- if info.size == 0 {
+ if info.isInvalid() {
return -1
}
if s := ss.next(info); s != ssSuccess {
@@ -424,7 +424,7 @@ func (f Form) nextBoundary(src input, nsrc int, atEOF bool) int {
}
fd := formTable[f]
info := fd.info(src, 0)
- if info.size == 0 {
+ if info.isInvalid() {
if atEOF {
return 1
}
@@ -435,7 +435,7 @@ func (f Form) nextBoundary(src input, nsrc int, atEOF bool) int {

for i := int(info.size); i < nsrc; i += int(info.size) {
info = fd.info(src, i)
- if info.size == 0 {
+ if info.isInvalid() {
if atEOF {
return i
}
@@ -465,7 +465,7 @@ func lastBoundary(fd *formInfo, b []byte) int {
if p == -1 {
return -1
}
- if info.size == 0 { // ends with incomplete rune
+ if info.isInvalid() { // ends with incomplete rune
if p == 0 { // starts with incomplete rune
return -1
}
@@ -504,7 +504,7 @@ func lastBoundary(fd *formInfo, b []byte) int {
func decomposeSegment(rb *reorderBuffer, sp int, atEOF bool) int {
// Force one character to be consumed.
info := rb.f.info(rb.src, sp)
- if info.size == 0 {
+ if info.isInvalid() {
return 0
}
if s := rb.ss.next(info); s == ssStarter {
@@ -528,7 +528,7 @@ func decomposeSegment(rb *reorderBuffer, sp int, atEOF bool) int {
break
}
info = rb.f.info(rb.src, sp)
- if info.size == 0 {
+ if info.isInvalid() {
if !atEOF {
return int(iShortSrc)
}
--
2.45.4

26 changes: 12 additions & 14 deletions SPECS/coredns/coredns.spec
Original file line number Diff line number Diff line change
Expand Up @@ -3,13 +3,7 @@
# set commit number that corresponds to the github tag for the version
%global coredns_gitcommit "6e11ebddfc13bfca683fcbcae72cc4af6de47dd2"

Summary: Fast and flexible DNS server
Name: coredns
Version: 1.11.4
Release: 19%{?dist}
License: Apache License 2.0
Vendor: Microsoft Corporation
Distribution: Azure Linux
Release: 20%{?dist}
Group: System Environment/Libraries
URL: https://github.com/coredns/coredns
#Source0: https://github.com/coredns/coredns/archive/v%%{version}.tar.gz
Expand Down Expand Up @@ -53,11 +47,9 @@ Patch14: CVE-2026-32936.patch
Patch15: CVE-2026-33489.patch
Patch16: CVE-2026-33190.patch
Patch17: CVE-2026-39821.patch
Patch18: CVE-2026-62299.patch
Patch19: CVE-2026-62994.patch

BuildRequires: golang < 1.25

Patch18: CVE-2026-56852.patch
Patch19: CVE-2026-62299.patch
Patch20: CVE-2026-62994.patch
%description
CoreDNS is a fast and flexible DNS server.

Expand Down Expand Up @@ -96,18 +88,24 @@ go install github.com/fatih/faillint@latest && \
%{_bindir}/%{name}

%changelog
* Wed Jul 22 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-19
* Mon Jul 27 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-20
- Patch for CVE-2026-62994

* Fri Jul 17 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-18
* Mon Jul 27 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-19
- Patch for CVE-2026-62299

* Mon Jul 27 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-18
- Patch for CVE-2026-56852

* Wed May 27 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-17
- Patch for CVE-2026-39821

* Wed May 06 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-16
- Patch for CVE-2026-32936, CVE-2026-32934, CVE-2026-33489, CVE-2026-33190

* Wed May 06 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-16
- Patch for CVE-2026-32936, CVE-2026-32934, CVE-2026-33489, CVE-2026-33190

* Mon Mar 09 2026 Azure Linux Security Servicing Account <azurelinux-security@microsoft.com> - 1.11.4-15
- Patch for CVE-2026-26018, CVE-2026-26017

Expand Down
Loading