DescriptionHuzaifa S. Sidhpurwala
2020-08-18 04:39:33 UTC
As per upstream advisory:
In versions of BIND that use the libuv network manager (9.16.x is the only stable branch affected) an incorrectly specified maximum buffer size allows a specially crafted large TCP payload to trigger an assertion failure when it is received.
An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Comment 1Huzaifa S. Sidhpurwala
2020-08-18 04:39:37 UTC
Comment 2Huzaifa S. Sidhpurwala
2020-08-18 04:39:40 UTC
Statement:
This version only affects bind-9.16.x. Therefore versions of bind package shipped with Red Hat Enterprise Linux are not affected by this flaw.
Comment 3Huzaifa S. Sidhpurwala
2020-08-21 02:16:04 UTC