| Summary: | bind: CVE-2015-8000 responses with a malformed class attribute can trigger an assertion failure in db.c | ||
|---|---|---|---|
| Product: | [Build System, Metadata & Runtime] OE-Core | Reporter: | Sona Sarmadi <sona.sarmadi> |
| Component: | connectivity | Assignee: | Sona Sarmadi <sona.sarmadi> |
| Status: | RESOLVED FIXED | QA Contact: | |
| Severity: | major | ||
| Priority: | Medium+ | CC: | meta.mr.watcher, meta.watcher |
| Version: | unspecified | ||
| Target Milestone: | 1.8.2 | ||
| Hardware: | All | ||
| OS: | Multiple | ||
| Whiteboard: | |||
| OS type for building Yocto: | --- | Type of Regression: | --- |
| Verified: | Documentation change: | No (bug/feature does not impact docs) | |
|
Description
Sona Sarmadi
2015-12-18 08:01:54 UTC
Upstream commit applied to 9.9.8: https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=490970d0614214b477085adf5aa021690194b0b8 Reference: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-8000 There is one more CVE (CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c) but it affects only bind 9.9.8-P2 and bind 9.10.3-P2. Patch sent to fido, dizzy: http://patchwork.openembedded.org/patch/110443/ Patch sent for dizzy & Fido: dizzy: http://git.yoctoproject.org/cgit/cgit.cgi/poky-contrib/commit/?h=akuster/dizzy-next&id=7a99aa9ea73d5d12d73599c860644fc28efd5135 Fido: http://git.yoctoproject.org/cgit/cgit.cgi/poky/patch/?id=58f6a400d1df17fd89a475c62aeb7ad656439330 Remaining issue: backport the fix to jethro Patch has been sent for Jethro: Patchwork [jethro-next,4/8] bind: Security fix CVE-2015-8000 http://patchwork.openembedded.org/patch/114133/ Jethro patched: https://git.yoctoproject.org/cgit/cgit.cgi/poky/log/?h=jethro&qt=grep&q=CVE-2015-8000 Master is updated to 9.10.3-P3. This is fixed in all relevant branches. |