A named
instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (synth-from-dnssec
) enabled can be remotely terminated using a zone with a malformed NSEC record.
This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bind | Isc | 9.16.8 (including) | 9.16.41 (including) |
Bind | Isc | 9.18.11 (including) | 9.18.15 (including) |
Bind9 | Ubuntu | bionic | * |
Bind9 | Ubuntu | trusty | * |
Bind9 | Ubuntu | xenial | * |