Reachable Assertion in ISC BIND - CVE-2020-8621
Published: August 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in resolver.c while attempting QNAME minimization after forwarding. If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash.
Affected software
Gentoo Linux
Opensuse
Ubuntu
bind (Alpine package)
bind9 (Ubuntu package)
How to mitigate CVE-2020-8621
bind (Alpine package) - update to 9.16.6-r0
bind9 (Ubuntu package) - addressed in versions 1:9.10.3.dfsg.P4-8ubuntu1.17, 1:9.11.3+dfsg-1ubuntu1.13, 1:9.16.1-0ubuntu2.3