It is possible for an attackers zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that is shorter than the attackers zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set synth-from-dnssec yes; (which is the default).
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | RedHat | bind9.16-32:9.16.23-0.22.el8_10.12 | * |
| Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-16.el8_10.14 | * |
| Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-16.el8_10.14 | * |
| Red Hat Enterprise Linux 9 | RedHat | bind-32:9.16.23-40.el9_8.8 | * |
| Red Hat Hardened Images | RedHat | bind-main-9.20.26-0.1.hum1 | * |
Specified quantities include size, length, frequency, price, rate, number of operations, time, and others. Code may rely on specified quantities to allocate resources, perform calculations, control iteration, etc.