CVE-2017-3145: Improper fetch cleanup sequencing in the resolver can cause named to crash
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
Other sources
Improper sequencing during cleanup operations of upstream recursion fetch contexts in BIND can lead to a use-after-free error, triggering an assertion failure and crash in named.
Affected BIND versions acting as DNSSEC validating resolvers are currently known to crash with an assertion failure in netaddr.c due to this bug.
External References:
https://kb.isc.org/article/AA-01542
Upstream Patches:
ftp://ftp.isc.org/isc/bind9/9.9.11-P1/patches/CVE-2017-3145 ftp://ftp.isc.org/isc/bind9/9.10.6-P1/patches/CVE-2017-3145 ftp://ftp.isc.org/isc/bind9/9.11.2-P1/patches/CVE-2017-3145
— Red Hat
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3145?
CVE-2017-3145 is classified as a high severity vulnerability due to its potential to cause assertion failures and crashes in BIND.
How do I fix CVE-2017-3145?
To fix CVE-2017-3145, update BIND to the latest patched version as specified by your operating system provider.
What versions of BIND are affected by CVE-2017-3145?
CVE-2017-3145 affects BIND versions 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, and 9.10.0 to 9.10.6 among others.
Is CVE-2017-3145 a use-after-free vulnerability?
Yes, CVE-2017-3145 is a use-after-free vulnerability which can lead to crashes of the BIND service.
How can I verify if my system is vulnerable to CVE-2017-3145?
You can verify vulnerability to CVE-2017-3145 by checking the BIND version installed on your system against the affected versions list.