systemd: Infinite loop in the dns_packet_read_type_window() function
Published Oct 26, 2017
7.5
HIGHCVSS 3.1
EPSS 23.63%
Description
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.
Affected products
No data.
Configuration 1
- 223
- 224
- 225
- 226
- 227
- 228
- 229
- 230
- 231
- 232
- 233
- 234
- 235
Configuration 2
- 14.04
- 16.04
No data.
Red Hat Enterprise Linux 7
systemd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | systemd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7 as they did not include the vulnerable code.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 23.63% (0.23633) | 97.75th | v5 (v2026.06.15) |
| Jun 15, 2026 | 23.63% (0.23633) | 97.51th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.35% (0.00353) | 55.52th | v4 (v2025.03.14) |
| Dec 17, 2024 | 92.09% (0.92090) | 99.19th | v3 (v2023.03.01) |
| Jun 15, 2023 | 95.50% (0.95505) | 99.06th | v3 (v2023.03.01) |
| May 22, 2023 | 95.92% (0.95921) | 99.15th | v3 (v2023.03.01) |
| May 8, 2023 | 96.25% (0.96251) | 99.23th | v3 (v2023.03.01) |
| Apr 28, 2023 | 96.51% (0.96510) | 99.32th | v3 (v2023.03.01) |
| Mar 19, 2023 | 96.80% (0.96804) | 99.43th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.82% (0.96824) | 99.42th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.02% (0.01018) | 38.88th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.02% (0.01018) | 36.86th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.25% (0.01247) | 30.57th | v1 |
| Jan 6, 2022 | 1.25% (0.01247) | 29.93th | v1 |
| Sep 1, 2021 | 1.25% (0.01247) | 68.62th | v1 |
| Apr 14, 2021 | 1.25% (0.01247) | 0.00th | v1 |
References (9)
- http://www.securityfocus.com/bid/101600 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1039662 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-15908 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1507515 Issue Tracking
- https://github.com/systemd/systemd/pull/7184 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-15908
- https://usn.ubuntu.com/3558-1/ vendor-advisoryx_refsource_UBUNTUPatchThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-15908
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/101600 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1039662 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-15908 | Vendor Advisory | |
| https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1725351 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1507515 | Issue Tracking | |
| https://github.com/systemd/systemd/pull/7184 | x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-15908 | ||
| https://usn.ubuntu.com/3558-1/ | vendor-advisoryx_refsource_UBUNTUPatchThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-15908 |
Change history (0)
No recorded changes yet.