[Dnsmasq-discuss] [PATCH] Don't hand a NULL hostname to my_syslog() in slaac_ping_reply().

Martin Vlach userhuge at gmail.com
Wed Sep 30 23:00:05 UTC 2026


slaac_add_addrs() won't create SLAAC addresses for a lease without a
hostname, but addresses already attached to a lease stay around if the
hostname goes away later, e.g. via kill_name() when another client
claims the same name. A matching ICMPv6 echo reply then makes
slaac_ping_reply() pass lease->hostname == NULL to a %s format, which is
undefined behaviour (glibc and musl just print "(null)").

Log "*" in that case, like the lease file code in lease.c already does.

Co-Authored-By: Claude Sonnet 5.5 <noreply at anthropic.com>
---
Another one from the same BudgetScan run. On glibc/musl it's purely
cosmetic ("(null)" in the log), so take it or leave it.

It can happen without DHCPv6: a second DHCPv4 client claiming the same
(client supplied) name makes lease_set_hostname() call kill_name() on the
first lease while that one still has an unconfirmed SLAAC address
(backoff != 0), and the echo reply then hits the log line. Found by
reading the code, I haven't reproduced it at runtime. Builds fine (macOS
only).

 src/slaac.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/slaac.c b/src/slaac.c
index ca92ac0..f696fdb 100644
--- a/src/slaac.c
+++ b/src/slaac.c
@@ -204,7 +204,7 @@ void slaac_ping_reply(struct in6_addr *sender, unsigned char *packet, char *inte
 	    gotone = 1;
 	    inet_ntop(AF_INET6, sender, daemon->addrbuff, ADDRSTRLEN);
 	    if (!option_bool(OPT_QUIET_DHCP6))
-	      my_syslog(MS_DHCP | LOG_INFO, "SLAAC-CONFIRM(%s) %s %s", interface, daemon->addrbuff, lease->hostname); 
+	      my_syslog(MS_DHCP | LOG_INFO, "SLAAC-CONFIRM(%s) %s %s", interface, daemon->addrbuff, lease->hostname ? lease->hostname : "*"); 
 	  }
   
   lease_update_dns(gotone);



More information about the Dnsmasq-discuss mailing list