ISC issues temporary patch for zero-day BIND 9 DNS server flaw

News

ISC issues temporary patch for zero-day BIND 9 DNS server flaw

Hillary O’Rourke, Contributor

Internet Systems Consortium (ISC) today issued a temporary patch for a zero-day vulnerability in BIND 9 DNS servers that’s causing Internet servers to crash. The fix doesn’t repair the vulnerability, but instead prevents DNS servers from crashing while handling the error, ISC said in an advisory.

Organizations across the Internet began reporting crashes that were interrupting service on BIND 9 name servers after logging an error while performing recursive queries. ISC said it is investigating whether this is just a denial-of-service condition, or whether there active exploits in the wild.

 “Affected servers crashed after logging an error in query.c with the following message: “INSIST(! Dns_rdataset_isassociated(sigrdataset)),” ISC said in its advisory. “An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers with an assertion failure.”

Multiple versions of the BIND 9 platform have been affected, including all supported versions of ISC BIND 9, as well as BIND 9.4-ESV, 9.6-EV, 9.7.x and 9.8.x.

 “When a client query is handled, the code that processes the response to the client has to ask the cache for the records for the name that is being queried,” explained the ISC advisory. For this reason, there are two separate components of the patch: The first prevents the cache from returning

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

the inconsistent data, while the second prevents the server from crashing if it detects it’s been given an inconsistent answer.

Currently, there are no known workarounds. ISC is encouraging users to upgrade BIND to one of its patched versions in order to mitigate the issue.


Join the conversationComment

Share
Comments

    Results

    Contribute to the conversation

    All fields are required. Comments will appear at the bottom of the article.