CVE-2023-5679: Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution
A bad interaction between DNS64 and serve-stale may cause named to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Other sources
A bad interaction between DNS64 and serve-stale may cause named to crash with an assertion failure during recursive resolution, when both of these features are enabled.
— Red Hat
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-5679?
CVE-2023-5679 is considered a medium severity vulnerability due to its potential to cause crashes in affected systems.
How do I fix CVE-2023-5679?
To fix CVE-2023-5679, update BIND to versions 9.16.48, 9.18.24, or 9.19.21 to resolve the issue.
What systems are affected by CVE-2023-5679?
CVE-2023-5679 affects BIND versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, and 9.19.0 through 9.19.19.
What are the symptoms of CVE-2023-5679?
Symptoms of CVE-2023-5679 include assertion failures and crashes of the 'named' service when recursive resolution is in use.
Is there a workaround for CVE-2023-5679?
Disabling either DNS64 or serve-stale features may serve as a temporary workaround for CVE-2023-5679 until a patch is applied.