CVE-2023-5679
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
- Netapp Active Iq Unified Manager
- All versions
- Fedoraproject Fedora
- = 38, 39
- Fix
- Available
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-617
- NVD status
- Modified
- Published
- 2024-02-13
Fix
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.48, 9.18.24, 9.19.21, 9.16.48-S1, or 9.18.24-S1.
Workaround
Disabling serve-stale (with `stale-cache-enable no;` and `stale-answer-enable no;`) and/or disabling `dns64` makes the faulty code path impossible to reach, preventing this flaw from being exploitable.
No indexed exploits for CVE-2023-5679 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-5679 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.