#VU8961 Infinite loop in systemd - CVE-2017-15908
Published: October 26, 2017 / Updated: October 27, 2017
systemd
Freedesktop.org
Description
The vulnerability exists in systemd due to an infinite loop in the dns_packet_read_type_window() function in the 'systemd-resolved' service. A remote attacker can return specially crafted DNS NSEC resource record data to the connected target client system, trigger an infinite loop and cause the target systemd-resolve service to fail to respond.
Successful exploitation of the vulnerability results in denial of service.