CVE-2016-6170: Input Validation
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote authenticated users to cause a denial of service (primary DNS server crash) via a large UPDATE message.
Other sources
It was found that bind does not implement reasonable restrictions for zone sizes. This allows an explicitly configured primary DNS server for a zone to crash a secondary DNS server, affecting service of other zones hosted on the same secondary server.
CVE request:
http://seclists.org/oss-sec/2016/q3/19
Proposed patches:
https://github.com/sischkg/xfer-limit/blob/master/bind-9.10.3-xfer-limit-0.0.1.patch https://github.com/sischkg/xfer-limit/blob/master/bind-9.9.9-P1-xfer-limit-0.0.1.patch
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6170?
CVE-2016-6170 is classified as a denial of service vulnerability that can lead to crashes of secondary DNS servers.
How do I fix CVE-2016-6170?
To mitigate CVE-2016-6170, upgrade BIND to the latest version that is not affected by this vulnerability.
Which versions of BIND are affected by CVE-2016-6170?
CVE-2016-6170 affects ISC BIND versions through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1.
Can CVE-2016-6170 affect IXFR servers?
Yes, CVE-2016-6170 may allow IXFR servers to cause a denial of service through large IXFR responses.
What are the potential impacts of CVE-2016-6170?
The potential impacts of CVE-2016-6170 include denial of service attacks resulting in DNS server crashes.