CVE-2017-15908: High severity Systemd Project Systemd vulnerability
Published Oct 26, 2017
·Updated
In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dnspacketreadtypewindow() function of the 'systemd-resolved' service and cause a DoS of the affected service.
Affected Software
16 affected componentsFixes available
Systemd Project Systemd=223
Systemd Project Systemd=224
Systemd Project Systemd=225
Systemd Project Systemd=226
Systemd Project Systemd=227
Systemd Project Systemd=228
Systemd Project Systemd=229
Systemd Project Systemd=230
Systemd Project Systemd=231
Systemd Project Systemd=232
Systemd Project Systemd=233
Systemd Project Systemd=234
Systemd Project Systemd=235
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
debian/systemd
247.3-7+deb11u5247.3-7+deb11u7252.39-1~deb12u1252.38-1~deb12u1257.9-1~deb13u1259.1-1
Remediation
Patch Available
Patch Available
Event History
Oct 26, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:31 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·09:33 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:33 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-15908.
2
What is the severity of CVE-2017-15908?
The severity of CVE-2017-15908 is high, with a severity value of 7.5.
3
How does CVE-2017-15908 affect systemd?
CVE-2017-15908 affects systemd versions 223 through 235.
4
How can CVE-2017-15908 be exploited?
CVE-2017-15908 can be exploited by a remote DNS server sending a specially crafted DNS NSEC resource record.
5
Is there a fix for CVE-2017-15908?
Yes, there are fixes available for CVE-2017-15908. Please refer to the references for more information.