Ref: http://www.openwall.com/lists/oss-security/2015/12/15/14 CVE: CVE-2015-8000 Document Version: 2.0 Posting date: 15 December 2015 Program Impacted: BIND Versions affected: 9.0.x -> 9.9.8, 9.10.0 -> 9.10.3 Severity: Critical Exploitable: Remotely Description: An error in the parsing of incoming responses allows some records with an incorrect class to be accepted by BIND instead of being rejected as malformed. This can trigger a REQUIRE assertion failure when those records are subsequently cached. Intentional exploitation of this condition is possible and could be used as a denial-of-service vector against servers performing recursive queries. Impact: An attacker who can cause a server to request a record with a malformed class attribute can use this bug to trigger a REQUIRE assertion in db.c, causing named to exit and denying service to clients. The risk to recursive servers is high. Authoritative servers are at limited risk if they perform authentication when making recursive queries to resolve addresses for servers listed in NS RRSETs. CVSS Score: 7.1 CVSS Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:C) For more information on the Common Vulnerability Scoring System and to obtain your specific environmental score please visit: https://nvd.nist.gov/cvss.cfm?calculator&version=2&vector=(AV:N/AC:M/Au:N/C:N/I:N/A:C) Workarounds: None. Active exploits: No known active exploits. Solution: Upgrade to the patched release most closely related to your current version of BIND. Public open-source branches can be downloaded from http://www.isc.org/downloads. BIND 9 version 9.9.8-P2 BIND 9 version 9.10.3-P2 BIND 9 Supported Preview edition is a feature preview version of BIND provided exclusively to ISC Support customers. BIND 9 version 9.9.8-S3 Related Documents: See our BIND9 Security Vulnerability Matrix at https://kb.isc.org/article/AA-00913 for a complete listing of Security Vulnerabilities and versions affected.
Upstream commit applied to 9.9.8: https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=490970d0614214b477085adf5aa021690194b0b8 Reference: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2015-8000
There is one more CVE (CVE-2015-8461 bind: race condition when handling socket errors can lead to an assertion failure in resolver.c) but it affects only bind 9.9.8-P2 and bind 9.10.3-P2.
Patch sent to fido, dizzy: http://patchwork.openembedded.org/patch/110443/
Patch sent for dizzy & Fido: dizzy: http://git.yoctoproject.org/cgit/cgit.cgi/poky-contrib/commit/?h=akuster/dizzy-next&id=7a99aa9ea73d5d12d73599c860644fc28efd5135 Fido: http://git.yoctoproject.org/cgit/cgit.cgi/poky/patch/?id=58f6a400d1df17fd89a475c62aeb7ad656439330 Remaining issue: backport the fix to jethro
Patch has been sent for Jethro: Patchwork [jethro-next,4/8] bind: Security fix CVE-2015-8000 http://patchwork.openembedded.org/patch/114133/
Jethro patched: https://git.yoctoproject.org/cgit/cgit.cgi/poky/log/?h=jethro&qt=grep&q=CVE-2015-8000 Master is updated to 9.10.3-P3.
This is fixed in all relevant branches.