Back

HIGH

A specially crafted packet can cause named to leak memory

Published Oct 9, 2019

Description

A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.

Affected products

Remediation

Vendor solution

Upgrade to a version of BIND containing a fix for the memory leak.

>= BIND 9.11.5-P4 >= BIND 9.12.3-P4

Red Hat statement

Versions of bind package shipped with Red Hat Enterprise Linux 5, 6, and 7 did not ship the vulnerable code and therefore are not affected by this flaw. For more details please refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1679299#c7

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Oct 9, 2019
Updated Sep 16, 2024
Reserved Jan 17, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 21, 2019