Bug 1837604 (CVE-2020-12663) - CVE-2020-12663 unbound: infinite loop via malformed DNS answers received from upstream servers
Summary: CVE-2020-12663 unbound: infinite loop via malformed DNS answers received from...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2020-12663
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact: Petr Sklenar
URL:
Whiteboard:
Depends On: 1837609 1840257 1840258 1840259 1840260 1840261 1840262 1840263 1879513
Blocks: 1837616
TreeView+ depends on / blocked
 
Reported: 2020-05-19 17:40 UTC by Guilherme de Almeida Suckevicz
Modified: 2020-10-06 14:22 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-06-08 11:20:31 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2020:2510 0 None None None 2020-06-10 17:52:54 UTC
Red Hat Product Errata RHBA-2020:2536 0 None None None 2020-06-11 18:11:19 UTC
Red Hat Product Errata RHBA-2020:2537 0 None None None 2020-06-11 18:34:11 UTC
Red Hat Product Errata RHBA-2020:2887 0 None None None 2020-07-09 15:01:05 UTC
Red Hat Product Errata RHSA-2020:2414 0 None None None 2020-06-08 08:24:32 UTC
Red Hat Product Errata RHSA-2020:2416 0 None None None 2020-06-08 09:37:33 UTC
Red Hat Product Errata RHSA-2020:2418 0 None None None 2020-06-08 10:17:12 UTC
Red Hat Product Errata RHSA-2020:2419 0 None None None 2020-06-08 10:24:39 UTC
Red Hat Product Errata RHSA-2020:2640 0 None None None 2020-06-22 07:21:06 UTC
Red Hat Product Errata RHSA-2020:4181 0 None None None 2020-10-06 14:22:45 UTC

Description Guilherme de Almeida Suckevicz 2020-05-19 17:40:02 UTC
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.

References:
http://www.openwall.com/lists/oss-security/2020/05/19/5
https://nlnetlabs.nl/downloads/unbound/CVE-2020-12662_2020-12663.txt

Comment 1 Guilherme de Almeida Suckevicz 2020-05-19 17:40:27 UTC
Created unbound tracking bugs for this issue:

Affects: fedora-all [bug 1837609]

Comment 4 Riccardo Schirone 2020-06-03 11:26:57 UTC
In reply to comment #2:
> Upstream fix:
> https://github.com/NLnetLabs/unbound/commit/
> ba0f382eee814e56900a535778d13206b86b6d49

According to https://github.com/NLnetLabs/unbound/issues/243#issuecomment-637298509, the changes related to this particular CVE are only those in iterator/iter_scrub.c and util/data/dname.c. The other changes are for CVE-2020-12662.

Comment 5 errata-xmlrpc 2020-06-08 08:24:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2020:2414 https://access.redhat.com/errata/RHSA-2020:2414

Comment 6 errata-xmlrpc 2020-06-08 09:37:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2020:2416 https://access.redhat.com/errata/RHSA-2020:2416

Comment 7 errata-xmlrpc 2020-06-08 10:17:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions

Via RHSA-2020:2418 https://access.redhat.com/errata/RHSA-2020:2418

Comment 8 errata-xmlrpc 2020-06-08 10:24:37 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.1 Extended Update Support

Via RHSA-2020:2419 https://access.redhat.com/errata/RHSA-2020:2419

Comment 9 Product Security DevOps Team 2020-06-08 11:20:31 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2020-12663

Comment 10 errata-xmlrpc 2020-06-22 07:21:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2020:2640 https://access.redhat.com/errata/RHSA-2020:2640

Comment 13 errata-xmlrpc 2020-10-06 14:22:43 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.7 Extended Update Support

Via RHSA-2020:4181 https://access.redhat.com/errata/RHSA-2020:4181


Note You need to log in before you can comment on or make changes to this bug.