Sploitus

CVE-2023-5679

No indexed exploits for CVE-2023-5679 yet

A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

Netapp Active Iq Unified Manager
All versions
Fedoraproject Fedora
= 38, 39
Fix
Available
CVSS 3.1
7.5 HIGH
EPSS
1.2% (66th percentile)
Weakness
CWE-617
NVD status
Modified
Published
2024-02-13

Fix

Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.48, 9.18.24, 9.19.21, 9.16.48-S1, or 9.18.24-S1.

Workaround

Disabling serve-stale (with `stale-cache-enable no;` and `stale-answer-enable no;`) and/or disabling `dns64` makes the faulty code path impossible to reach, preventing this flaw from being exploitable.

CVE-2023-5679 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2023-5679 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2023-5679 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.