LWN.net Logo

bind9: denial of service

Package(s):bind9 CVE #(s):CVE-2011-4313
Created:November 17, 2011 Updated:November 30, 2011
Description:

From the ISC advisory:

Organizations across the Internet reported crashes interrupting service on BIND 9 nameservers performing recursive queries. Affected servers crashed after logging an error in query.c with the following message: "INSIST(! dns_rdataset_isassociated(sigrdataset))" Multiple versions were reported being affected, including all currently supported release versions of ISC BIND 9.

[...]

An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers with an assertion failure. ISC is working on determining the ultimate cause by which a record with this particular inconsistency is cached. At this time we are making available a patch which makes named recover gracefully from the inconsistency, preventing the abnormal exit.

Alerts:
CentOS CESA-2011:1496 2011-11-29
Oracle ELSA-2011-1496 2011-11-30
SUSE SUSE-SU-2011:1270-3 2011-11-30
Scientific Linux SL-bind-20111129 2011-11-29
CentOS CESA-2011:1496 2011-11-29
Red Hat RHSA-2011:1496-01 2011-11-29
Fedora FEDORA-2011-16002 2011-11-17
Fedora FEDORA-2011-16036 2011-11-17
SUSE SUSE-SU-2011:1270-2 2011-11-23
SUSE SUSE-SU-2011:1270-1 2011-11-22
SUSE SUSE-SU-2011:1268-1 2011-11-22
openSUSE openSUSE-SU-2011:1272-1 2011-11-22
Oracle ELSA-2011-1459 2011-11-18
Oracle ELSA-2011-1458 2011-11-18
CentOS CESA-2011:1459 2011-11-18
Scientific Linux SL-bind-20111117 2011-11-17
Mandriva MDVSA-2011:176-1 2011-11-17
Red Hat RHSA-2011:1458-01 2011-11-17
Debian DSA-2347-1 2011-11-16
Fedora FEDORA-2011-16057 2011-11-17
Oracle ELSA-2011-1458 2011-11-18
CentOS CESA-2011:1458 2011-11-18
Scientific Linux SL-bind-20111117 2011-11-17
Mandriva MDVSA-2011:176-2 2011-11-18
Red Hat RHSA-2011:1459-01 2011-11-17
Ubuntu USN-1264-1 2011-11-16
Mandriva MDVSA-2011:176 2011-11-16
Gentoo 201206-01 2012-06-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds