Infinite loop in systemd - CVE-2017-15908
Published: October 26, 2017 / Updated: October 27, 2017
systemd
Detailed vulnerability description
The vulnerability exists in systemd due to an infinite loop in the dns_packet_read_type_window() function in the 'systemd-resolved' service. A remote attacker can return specially crafted DNS NSEC resource record data to the connected target client system, trigger an infinite loop and cause the target systemd-resolve service to fail to respond.
Successful exploitation of the vulnerability results in denial of service.