Reachable Assertion in ISC BIND - CVE-2020-8620
Published: August 20, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in tcpdns.c when processing large TCP payloads. An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
Affected software
Gentoo Linux
Opensuse
Ubuntu
bind (Alpine package)
bind9 (Ubuntu package)
How to mitigate CVE-2020-8620
bind (Alpine package) - update to 9.16.6-r0
bind9 (Ubuntu package) - addressed in versions 1:9.10.3.dfsg.P4-8ubuntu1.17, 1:9.11.3+dfsg-1ubuntu1.13, 1:9.16.1-0ubuntu2.3