Back

HIGH

A malformed request can trigger an assertion failure in badcache.c

Published Jan 16, 2019

Description

While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND 9.10.5-S1 to 9.10.5-S4, 9.10.6-S1, 9.10.6-S2.

Affected products

Remediation

Vendor solution

Upgrade to the patched release.

No publicly released versions of BIND are affected

BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.

BIND 9 version 9.10.6-S3

Red Hat statement

This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 5, 6 and 7 as they did not include the vulnerable code.

Metrics

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jan 16, 2019
Updated Sep 17, 2024
Reserved Jan 17, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 28, 2018