plugin/file: return SERVFAIL on self-referential CNAME loops (#8475)

A CNAME whose target is its own owner name is chased by externalLookup
until the depth cap, appending the same record on every pass. The reply
was NOERROR with the CNAME repeated ten times.

Self-referential DNAME already returns SERVFAIL, as do wildcard CNAME
loops. Return SERVFAIL here too. The check runs on the CNAME chase path
only, so normal responses are unaffected.

Fixes #6421

Signed-off-by: baltasarblanco <baltablanco9008@gmail.com>
This commit is contained in:
Baltasar Blanco
2026-09-08 16:21:54 -03:00
committed by GitHub
parent e1d3fe6bc6
commit dea2f90f24
2 changed files with 11 additions and 1 deletions

View File

@@ -385,6 +385,11 @@ func (z *Zone) externalLookup(ctx context.Context, state request.Request, tr *tr
Redo:
cname := elem.Type(dns.TypeCNAME)
if len(cname) > 0 {
// A CNAME that points to its own owner name can only loop.
if dns.CanonicalName(cname[0].Header().Name) == dns.CanonicalName(cname[0].(*dns.CNAME).Target) {
return nil, nil, nil, ServerFailure
}
rrs = append(rrs, cname...)
if do {