CVE-2017-3135: Combination of DNS64 and RPZ Can Lead to Crash
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3135?
CVE-2017-3135 has been classified with high severity due to potential assertion failures and NULL pointer dereferencing.
How do I fix CVE-2017-3135?
To address CVE-2017-3135, upgrade to a patched version of BIND, such as 1:9.11.5.P4+dfsg-5.1+deb10u7 or later.
Which versions of BIND are affected by CVE-2017-3135?
CVE-2017-3135 affects BIND versions 9.9.3-S1 through 9.9.9-S7, among others.
Can CVE-2017-3135 lead to service disruption?
Yes, CVE-2017-3135 can cause service interruptions due to assertion failures and inconsistent query processing.
Is there a workaround for CVE-2017-3135 while waiting for a patch?
There are no official workarounds for CVE-2017-3135; upgrading to a secure version is recommended for mitigation.