Back

HIGH

Destroying a TLS session early causes assertion failure

Published May 19, 2022

Description

On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND: BIND 9.18.3 or BIND 9.19.1.

Red Hat statement

This flaw only affects BIND 9.18.0 -> 9.18.2 and BIND 9.19.0, whereas Red Hat ships BIND-9.16 and lower versions. Therefore, versions of BIND shipped with Red Hat Products are not affected by this flaw. For RHEL-9, DHCP uses BIND 9 libraries (bind-9.11.x) for some services. Hence, DHCP shipped with RHEL-9 is also not affected.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published May 19, 2022
Updated Sep 17, 2024
Reserved Mar 30, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date May 18, 2022