Back

MEDIUM

bind: malformed packet sent to rndc can trigger assertion failure

Published Mar 9, 2016

Description

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

Affected products

Remediation

Red Hat mitigation

Restrict access to the control channel (by using the "controls" configuration statement in named.conf) to allow connection only from trusted systems. Note that if no "controls" statement is present, named defaults to allowing control channel connections only from localhost (127.0.0.1 and ::1) if and only if the file rndc.key exists in the configuration directory and contains valid key syntax. If rndc.key is not present and no "controls" statement is present in named.conf, named will not accept commands on the control channel.

Metrics

Weaknesses (1)

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 9, 2016
Updated Aug 5, 2024
Reserved Jan 4, 2016
CISA Vulnrichment
Updated Jul 23, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 9, 2016