Null pointer dereference in systemd - CVE-2017-9217

 

Null pointer dereference in systemd - CVE-2017-9217

Published: July 4, 2017 / Updated: August 24, 2017


Vulnerability identifier: #VU7301
CSH Severity: Medium
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9217
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to null pointer dereference in dns_packet_is_reply_for function in resolved-dns-packet.c file. A remote attacker can supply a specially crafted DNS response with an empty question section to cause the daemon to crash.

Successful exploitation of the vulnerability results in denial of service.

Affected software

systemd
Arch Linux
Fedora

How to mitigate CVE-2017-9217

Update to the latest version.

systemd - addressed in versions 229-20.fc24, 231-15.fc25, 233-4.fc26

External References

Related Security Bulletins