CVE-2017-3136: An error handling synthesized records could cause an assertion failure when using DNS64 with "break-dnssec yes;"
A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met.
Servers are at risk if they are configured to use DNS64 and if the option "break-dnssec yes;" is in use.
External References:
https://kb.isc.org/article/AA-01465
Mitigation:
Servers which have configurations which require DNS64 and "break-dnssec yes;" should upgrade. Servers which are not using these features in conjunction are not at risk from this defect.
Other sources
A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.0 -> 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0 -> 9.11.0-P3, 9.11.1b1->9.11.1rc1, 9.9.3-S1 -> 9.9.9-S8.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3136?
CVE-2017-3136 is classified as a critical denial-of-service vulnerability that can cause a server using DNS64 to crash.
How do I fix CVE-2017-3136?
To fix CVE-2017-3136, update your BIND software to a version that has patched the vulnerability, such as 1:9.11.5.P4+dfsg-5.1+deb10u7 or higher.
Which versions of BIND are affected by CVE-2017-3136?
CVE-2017-3136 affects various versions of BIND including, but not limited to, versions prior to 9.11.5.P4, 9.10.4, and 9.9.9.
What types of attacks can CVE-2017-3136 be exploited for?
CVE-2017-3136 can be exploited to carry out denial-of-service attacks against servers using the DNS64 feature, causing them to terminate unexpectedly.
Are there any specific environments where CVE-2017-3136 is a concern?
CVE-2017-3136 is particularly concerning for servers configured to use the DNS64 feature, commonly found in environments supporting IPv6.