Race condition in ISC BIND - CVE-2019-6471

 

Race condition in ISC BIND - CVE-2019-6471

Published: October 7, 2019


Vulnerability identifier: #VU21568
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6471
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a race condition when processing DNS requests in dispatch.c. A remote attacker can send specially crafted DNS packets to the affected daemon, trigger a REQUIRE assertion failure and crash the DNS server.

Affected software

ISC BIND
Anolis OS
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Fedora
bind (Alpine package)
dnsperf
dhcp
bind
bind-pkcs11
bind-libs-lite
bind-chroot
bind-devel
bind-export-devel
bind-export-libs
bind-libs
python3-bind
bind-license
bind-utils
bind-sdb-chroot
bind-sdb
bind-pkcs11-utils
bind-pkcs11-libs
bind-pkcs11-devel
bind-lite-devel
bind-dyndb-ldap

How to mitigate CVE-2019-6471

Install updates from vendor's website.

ISC BIND - addressed in versions 9.11.8, 9.11.8-S1, 9.12.4-P2, 9.14.3, 9.15.1
bind (Alpine package) - update to 9.11.8-r0
dnsperf - addressed in versions 2.3.0-1.fc29, 2.3.0-1.fc30, 2.3.2-1.fc29
dhcp - addressed in versions 4.3.6-32.fc29, 4.3.6-34.fc29, 4.3.6-35.fc30
bind - addressed in versions 9.11.8-1.fc29, 9.11.8-1.fc30, 9.11.10-1.fc29
bind-pkcs11 - update to 9.11.36-3
bind-libs-lite - update to 9.11.36-3
bind - update to 9.11.36-3
bind-chroot - update to 9.11.36-3
bind-devel - update to 9.11.36-3
bind-export-devel - update to 9.11.36-3
bind-export-libs - update to 9.11.36-3
bind-libs - update to 9.11.36-3
python3-bind - update to 9.11.36-3
bind-license - update to 9.11.36-3
bind-utils - update to 9.11.36-3
bind-sdb-chroot - update to 9.11.36-3
bind-sdb - update to 9.11.36-3
bind-pkcs11-utils - update to 9.11.36-3
bind-pkcs11-libs - update to 9.11.36-3
bind-pkcs11-devel - update to 9.11.36-3
bind-lite-devel - update to 9.11.36-3
bind-dyndb-ldap - addressed in versions 11.1-17.fc29, 11.1-17.fc30, 11.1-19.fc29

External References

Related Security Bulletins