In systemd 223 through 235, a remote DNS server can respond with a custom crafted DNS NSEC resource record to trigger an infinite loop in the dns_packet_read_type_window() function of the 'systemd-resolved' service and cause a DoS of the affected service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade systemd | Jul 30, 2024 | Oct 26, 2017 |
| Suse | — | Upgrade systemdUpgrade systemd-docUpgrade systemd-containerUpgrade libsystemd0Upgrade systemd-sysvinitUpgrade systemd-langUpgrade systemd-coredumpUpgrade systemd-bash-completionUpgrade systemd-journal-remoteUpgrade systemd-32bitUpgrade libudev-develUpgrade udevUpgrade libudev1-32bitUpgrade libsystemd0-32bitUpgrade libudev1Upgrade systemd-devel | Jan 31, 2018 | Oct 26, 2017 |
| Ubuntu | — | Upgrade systemd | Nov 21, 2017 | Oct 26, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 26, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub