CVE-2016-2848: Input Validation
A packet with a malformed options section can be used to deliberately trigger an assertion failure affecting versions of BIND which do not contain change #3548.
A server vulnerable to this defect can be forced to exit with an assertion failure if it receives a malformed packet. Authoritative and recursive servers are both vulnerable.
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=blob;f=CHANGES has more information on change #3548. The commit corresponding to this change is https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=4adf97c32fcca7d00e5756607fd045f2aab9c3d4.
Other sources
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2848?
CVE-2016-2848 has a medium severity impact as it can cause an assertion failure in BIND, leading to server crashes.
How do I fix CVE-2016-2848?
To fix CVE-2016-2848, upgrade to a non-vulnerable version of BIND that includes the fix from change #3548.
Which versions are affected by CVE-2016-2848?
Versions of BIND from 9.1 to 9.2.9, including various release candidates, are affected by CVE-2016-2848.
What are the consequences of CVE-2016-2848 vulnerability?
The consequences of CVE-2016-2848 include BIND servers being forced to exit unexpectedly when they receive malformed packets.
Can CVE-2016-2848 be exploited remotely?
Yes, CVE-2016-2848 can be exploited remotely by sending specially crafted packets to affected BIND servers.