Back

HIGH

systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new

Published Jun 28, 2017

Description

In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.

Affected products

Remediation

Red Hat statement

This issue did not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 28, 2017
Updated Aug 5, 2024
Reserved Jun 5, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 27, 2017