REDHAT-BUG-2479772: Use After Free
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients" limit is reached (as would occur during a query flood), and that same DNS message is discarded per the limit, there is a brief window of time while the SIG(0) validation may attempt to read the now-discarded DNS message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2479772?
The severity of REDHAT-BUG-2479772 is high with a score of 7.
What vulnerabilities are associated with REDHAT-BUG-2479772?
REDHAT-BUG-2479772 is associated with Use After Free and Race Condition vulnerabilities.
How do I fix REDHAT-BUG-2479772?
To fix REDHAT-BUG-2479772, ensure you update ISC BIND to the latest patched version that addresses this vulnerability.
What are the potential impacts of REDHAT-BUG-2479772?
The potential impacts of REDHAT-BUG-2479772 include undefined behavior and possible exploitation leading to a use-after-free violation.
Who is affected by REDHAT-BUG-2479772?
Users and administrators running ISC BIND are affected by REDHAT-BUG-2479772.