diff --git a/CHANGES b/CHANGES index 855a42e48b..902e52fbd8 100644 --- a/CHANGES +++ b/CHANGES @@ -16,7 +16,9 @@ 5480. [placeholder] -5479. [placeholder] +5479. [security] named could crash in certain query resolution scenarios + where QNAME minimization and forwarding were both + enabled. (CVE-2020-8621) [GL #1997] 5478. [security] It was possible to trigger an assertion failure by sending a specially crafted large TCP DNS message. diff --git a/doc/notes/notes-current.rst b/doc/notes/notes-current.rst index 0b21089508..7fc7d91bd8 100644 --- a/doc/notes/notes-current.rst +++ b/doc/notes/notes-current.rst @@ -20,6 +20,15 @@ Security Fixes ISC would like to thank Emanuel Almeida of Cisco Systems, Inc. for bringing this vulnerability to our attention. [GL #1996] +- ``named`` could crash after failing an assertion check in certain + query resolution scenarios where QNAME minimization and forwarding + were both enabled. To prevent such crashes, QNAME minimization is now + always disabled for a given query resolution process, if forwarders + are used at any point. This was disclosed in CVE-2020-8621. + + ISC would like to thank Joseph Gullo for bringing this vulnerability + to our attention. [GL #1997] + Known Issues ~~~~~~~~~~~~