Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x4c-8qp9-8ggh

Опубликовано: 16 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

If a named caching resolver is configured with serve-stale-enable yes, and with stale-answer-client-timeout set to 0 (the only allowable value other than disabled), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1.

If a named caching resolver is configured with serve-stale-enable yes, and with stale-answer-client-timeout set to 0 (the only allowable value other than disabled), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1.

EPSS

Процентиль: 4%
0.00021
Низкий

7.5 High

CVSS3

Дефекты

CWE-617

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

possible assertion failure when using the ‘stale-answer-client-timeout 0’ option

CVSS3: 5.3
redhat
около 1 месяца назад

An assertion failure flaw has been discovered in bind. If a `named` caching resolver is configured with `serve-stale-enable`: `yes`, and with `stale-answer-client-timeout` set to `0`, and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure.

CVSS3: 7.5
nvd
около 1 месяца назад

If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1.

CVSS3: 7.5
debian
около 1 месяца назад

If a `named` caching resolver is configured with `serve-stale-enable` ...

EPSS

Процентиль: 4%
0.00021
Низкий

7.5 High

CVSS3

Дефекты

CWE-617