A denial of service flaw was found in the way BIND followed DNS delegations. A remote attacker could use a specially crafted zone containing a large number of referrals which, when looked up and processed, would cause named to use excessive amounts of memory or crash. The BIND 9.9.6-P1 and 9.10.1-P1 release fix the following flaw: "" By making use of maliciously-constructed zones or a rogue server, an attacker can exploit an oversight in the code BIND 9 uses to follow delegations in the Domain Name Service, causing BIND to issue unlimited queries in an attempt to follow the delegation. This can lead to resource exhaustion and denial of service (up to and including termination of the named server process.) All recursive resolvers are affected. Authoritative servers can be affected if an attacker can control a delegation traversed by the authoritative server in servicing the zone. "" It is reported that versions 9.0.x to 9.8.x, 9.9.0 to 9.9.6, and 9.10.0 to 9.10.1 are affected. External References: https://kb.isc.org/article/AA-01216/74/CVE-2014-8500%3A-A-Defect-in-Delegation-Handling-Can-Be-Exploited-to-Crash-BIND.html Upstream commits for bind 9.9: https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=603a0e2637b35a2da820bc807f69bcf09c682dce https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=711e833921d3dd67df7515438e152bbfdb2c1249
Please back port to 1.6.3 and 1.7.1
Was fixed in master with http://git.yoctoproject.org/cgit.cgi/poky/commit/?id=6ceceb10be5213ca3c7eb7043caebadc106da3d7
already in Dizzy. http://git.yoctoproject.org/cgit/cgit.cgi/poky/commit/?h=dizzy&id=9d20b675dd5fda3e3e8ecc9059ee7084266775cb
Fixed in daisy too: http://git.yoctoproject.org/cgit.cgi/poky/commit/?h=daisy&id=7a43fb95d1dc559b6c240f8d0c07082b3988c27c