Reachable Assertion in ISC BIND - CVE-2020-8623
Published: August 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when processing DNS query for a zone signed with RSA. A remote attacker can send a specially crafted query and crash the DNS server.
Successful exploitation of the vulnerability requires that BIND is built with "--enable-native-pkcs11".
Affected software
Gentoo Linux
CentOS
Anolis OS
Red Hat Enterprise Linux for IBM System z (Structure A)
Red Hat Enterprise Linux for Power 9
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power, big endian - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
Opensuse
Ubuntu
openEuler
Fedora
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bind (Alpine package)
bind (Red Hat package) main
bind9 (Debian package)
dnsperf
bind9 (Ubuntu package)
bind-export-libs
bind-export-devel
bind-license
bind-utils
bind-sdb-chroot
bind-sdb
bind-pkcs11-utils
bind-pkcs11-libs
bind-pkcs11-devel
bind-pkcs11
bind-lite-devel
bind-libs-lite
bind-libs
bind
bind-chroot
bind-devel
python3-bind
bind-debuginfo
bind-debugsource
bind-dyndb-ldap
Data Computing Appliance (DCA)
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-8623
bind (Alpine package) - update to 9.16.6-r0
bind (Red Hat package) main - addressed in versions 9.9.4-74.el7_6.5, 9.11.4-9.P2.el7_7.3, 9.11.4-26.P2.el7_9.2, 9.11.20-5.el8
bind9 (Debian package) - update to 9.11.5.P4+dfsg-5.1+deb10u2
dnsperf - addressed in versions 2.3.4-2.fc31, 2.3.4-2.fc32
Data Computing Appliance (DCA) - update to 4.3.0.0
Red Hat OpenShift Container Platform - update to 4.5.20
bind9 (Ubuntu package) - addressed in versions 1:9.10.3.dfsg.P4-8ubuntu1.17, 1:9.11.3+dfsg-1ubuntu1.13, 1:9.16.1-0ubuntu2.3
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-libs - update to 9.11.21-3
bind - update to 9.11.21-3
python3-bind - update to 9.11.21-3
bind-chroot - update to 9.11.21-3
bind-debuginfo - update to 9.11.21-3
bind-debugsource - update to 9.11.21-3
bind-devel - update to 9.11.21-3
bind-export-devel - update to 9.11.21-3
bind-libs - update to 9.11.21-3
bind-libs-lite - update to 9.11.21-3
bind-pkcs11 - update to 9.11.21-3
bind-pkcs11-devel - update to 9.11.21-3
bind-sdb - update to 9.11.21-3
bind-sdb-chroot - update to 9.11.21-3
bind-utils - update to 9.11.21-3
bind - addressed in versions 9.11.22-1.fc31, 9.11.22-1.fc32
python3-bind - update to 9.11.36-3
bind-dyndb-ldap - addressed in versions 11.2-4.fc31, 11.3-2.fc32
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Slackware Linux update for bind
- Gentoo update for BIND
- Debian update for bind9
- Reachable Assertion in bind (Alpine package)
- OpenSUSE Linux update for bind
- OpenSUSE Linux update for bind
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 7.6 update for bind
- Red Hat Enterprise Linux 7 update for bind
- CentOS 7 update for bind
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Red Hat Enterprise Linux 7 update for bind
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- openEuler 20.03 LTS update for bind
- Anolis OS update for bind (Anolis OS 8.6)
- Anolis OS update for bind
- Ubuntu update for bind9
- Fedora 32 update for bind, bind-dyndb-ldap, dnsperf
- Fedora 31 update for bind, bind-dyndb-ldap, dnsperf