plugin/loadbalance: validate the response before dereferencing it in WriteMsg (#8523)

This commit is contained in:
Baltasar Blanco
2026-09-08 00:50:54 -03:00
committed by GitHub
parent 9fb1859b23
commit 71a60e140b
2 changed files with 59 additions and 0 deletions

View File

@@ -1,6 +1,8 @@
package loadbalance
import (
"fmt"
"github.com/miekg/dns"
)
@@ -17,10 +19,21 @@ type LoadBalanceResponseWriter struct {
// WriteMsg implements the dns.ResponseWriter interface.
func (r *LoadBalanceResponseWriter) WriteMsg(res *dns.Msg) error {
if res == nil {
return fmt.Errorf("loadbalance: response message is nil")
}
if res.Rcode != dns.RcodeSuccess {
return r.ResponseWriter.WriteMsg(res)
}
// A response can arrive with no question section at all, in which case
// there is nothing to key the shuffle on and Question[0] below would
// panic. Pass it through untouched, as the transfer types do.
if len(res.Question) == 0 {
return r.ResponseWriter.WriteMsg(res)
}
if res.Question[0].Qtype == dns.TypeAXFR || res.Question[0].Qtype == dns.TypeIXFR {
return r.ResponseWriter.WriteMsg(res)
}