2
0
mirror of https://gitlab.isc.org/isc-projects/bind9 synced 2025-08-31 14:35:26 +00:00

Add release note for GL #3394

This commit is contained in:
Michał Kępień
2022-09-08 11:11:30 +02:00
parent e802beedfc
commit 672072812c

View File

@@ -15,7 +15,14 @@ Notes for BIND 9.19.5
Security Fixes
~~~~~~~~~~~~~~
- None.
- Previously, there was no limit to the number of database lookups
performed while processing large delegations, which could be abused to
severely impact the performance of :iscman:`named` running as a
recursive resolver. This has been fixed. (CVE-2022-2795)
ISC would like to thank Yehuda Afek from Tel-Aviv University and Anat
Bremler-Barr & Shani Stajnrod from Reichman University for bringing
this vulnerability to our attention. :gl:`#3394`
Known Issues
~~~~~~~~~~~~