CVE-2018-5740: A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named

Published Aug 8, 2018
·
Updated

"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

Other sources

BIND through versions 9.8.8, 9.9.13, 9.10.8, 9.11.4, 9.12.2 and 9.13.2 have a flaw in the "deny-answer-aliases" feature that can cause an INSIST assertion failure in named. A remote attacker could exploit this to cause named to crash.

Only servers which have explicitly enabled the "deny-answer-aliases" feature are at risk and disabling the feature prevents exploitation.

Red Hat

Affected Software

31 affected componentsFixes available
redhat/bind<9.9.13
9.9.13
redhat/bind<9.10.8
9.10.8
redhat/bind<9.11.4
9.11.4
redhat/bind<9.12.2
9.12.2
ISC BIND>=9.7.0<9.8.8
ISC BIND>=9.9.0<9.9.13
ISC BIND>=9.10.0<9.10.8
ISC BIND>=9.11.0<9.11.4
ISC BIND>=9.12.0<9.12.2
ISC BIND>=9.13.0<9.13.2
redhat Enterprise Linux Desktop=6.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Server=6.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Eus=7.5
redhat Enterprise Linux Server Eus=7.6
redhat Enterprise Linux Workstation=6.0
redhat Enterprise Linux Workstation=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
NetApp Data Ontap Edge
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
HP HP-UX
openSUSE Leap=15.0
openSUSE Leap=15.1
openSUSE Leap=42.3
debian/bind9
1:9.16.50-1~deb11u21:9.16.50-1~deb11u41:9.18.41-1~deb12u11:9.18.44-1~deb12u11:9.20.15-1~deb13u11:9.20.18-1~deb13u11:9.20.19-1

Remediation

Mitigation

Disable use of "deny-answer-aliases" feature

Information

Most operators will not need to make any changes unless they are using the "deny-answer-aliases" feature (which is described in the BIND 9 Adminstrator Reference Manual section 6.2.) "deny-answer-aliases" is off by default; only configurations which explicitly enable it can be affected by this defect. If you are using "deny-answer-aliases", upgrade to the patched release most closely related to your current version of BIND. 9.9.13-P1 9.10.8-P1 9.11.4-P1 9.12.2-P1 BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. 9.11.3-S3

Event History

Jan 16, 2019
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·08:29 PM
DescriptionSeverityWeaknessAffected Software
Feb 20, 2026
Data Sourced
via Ubuntu·08:25 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·08:26 PM
Description
Feb 21, 2026
Data Sourced
via Debian·08:26 PM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-5740?

CVE-2018-5740 is classified as having a medium severity due to its potential impact on DNS rebinding attacks.

2

How do I fix CVE-2018-5740?

To fix CVE-2018-5740, it is recommended to upgrade to BIND version 9.9.13 or later, or the fixed versions provided by your Linux distribution.

3

What systems are affected by CVE-2018-5740?

CVE-2018-5740 affects various versions of the BIND DNS software, specifically versions before 9.9.13, 9.10.8, 9.11.4, and 9.12.2.

4

Is CVE-2018-5740 specific to certain Linux distributions?

Yes, CVE-2018-5740 affects BIND installations on different Linux distributions including Red Hat and Debian.

5

What are the potential risks of CVE-2018-5740?

The main risk associated with CVE-2018-5740 is the exposure to DNS rebinding attacks which could allow attackers to compromise user privacy and data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203