CVE-2023-5517: Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled
A flaw in query-handling code can cause named to exit prematurely with an assertion failure when:
- nxdomain-redirect <domain>; is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Other sources
A flaw in query-handling code can cause named to exit prematurely with an assertion failure when:
- nxdomain-redirect <domain>; is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response.
— Red Hat
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5517?
CVE-2023-5517 has a high severity rating due to the potential for causing named to exit prematurely.
How do I fix CVE-2023-5517?
To fix CVE-2023-5517, upgrade to bind version 9.16.48, 9.18.24, or 9.19.21 or later.
What systems are affected by CVE-2023-5517?
CVE-2023-5517 affects various versions of ISC BIND, Red Hat bind, and Debian bind9 installations.
What scenarios trigger CVE-2023-5517?
CVE-2023-5517 is triggered when nxdomain-redirect is configured alongside a PTR query for an RFC 1918 address.
How can I identify if my system is vulnerable to CVE-2023-5517?
You can identify vulnerability to CVE-2023-5517 by checking if you are running an affected version of bind.