Описание
An attacker may be able to cause a named resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the named resolver will encounter a use-after-free bug, and abort.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
A flaw was found in BIND 9. A remote attacker can cause a named resolver to stop functioning (Denial of Service) by inducing the victim resolver to send multiple queries for a DNSSEC-signed zone. If the attacker's authoritative server responds with a specific sequence of crafted answers that arrive with particular timing, a use-after-free vulnerability is triggered, leading to the resolver's abortion.
Отчет
This Moderate impact denial of service vulnerability in BIND 9's named resolver can lead to service unavailability. Exploitation requires an attacker to operate an authoritative DNS server and specifically induce a vulnerable resolver to query it for a DNSSEC-signed zone. The attack relies on a precise sequence and timing of crafted DNSSEC responses, limiting its broader applicability.
Меры по смягчению последствий
To mitigate this issue, consider disabling DNSSEC validation on named resolvers if it is not a strict requirement for your environment. This can be achieved by setting dnssec-validation no; in the named.conf file. Disabling DNSSEC validation will prevent the resolver from processing DNSSEC-signed zones, thereby avoiding this specific vulnerability, but it will also remove the security benefits provided by DNSSEC. After modifying the configuration, the named service must be reloaded or restarted for the changes to take effect.
sudo systemctl reload named
sudo systemctl restart named
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 6 | bind | Not affected | ||
| Red Hat Enterprise Linux 7 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 8 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 8 | bind9.16 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 9 | bind9.18 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | dhcp | Not affected | ||
| Red Hat Hardened Images | bind | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.9 Medium
CVSS3
Связанные уязвимости
(An attacker may be able to cause a `named` resolver to abort. The atta ...)
An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
An attacker may be able to cause a `named` resolver to abort. The atta ...
An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
5.9 Medium
CVSS3