Reachable Assertion in ISC BIND - CVE-2020-8621

 

Reachable Assertion in ISC BIND - CVE-2020-8621

Published: August 20, 2020


Vulnerability identifier: #VU45820
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8621
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion in resolver.c while attempting QNAME minimization after forwarding. If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash.


Affected software

ISC BIND
Gentoo Linux
Opensuse
Ubuntu
bind (Alpine package)
bind9 (Ubuntu package)

How to mitigate CVE-2020-8621

Install updates from vendor's website.

ISC BIND - addressed in versions 9.16.6, 9.17.4
bind (Alpine package) - update to 9.16.6-r0
bind9 (Ubuntu package) - addressed in versions 1:9.10.3.dfsg.P4-8ubuntu1.17, 1:9.11.3+dfsg-1ubuntu1.13, 1:9.16.1-0ubuntu2.3

External References

Related Security Bulletins