CVE-2018-5744: A specially crafted packet can cause named to leak memory
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-5744.
What is the severity of CVE-2018-5744?
The severity of CVE-2018-5744 is high.
Which versions of BIND are affected by CVE-2018-5744?
Versions 9.10.7 to 9.10.8-P1, 9.11.3 to 9.11.5-P1, 9.12.0 to 9.12.3-P1, and 9.10.7-S1 to 9.11.5-S3 of BIND 9 Supported Preview Edition are affected by CVE-2018-5744.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for CVE-2018-5744 is 772.
How can I fix CVE-2018-5744?
To fix CVE-2018-5744, it is recommended to upgrade BIND to a patched version provided by ISC.