Critical severity9.8NVD Advisory· Published Oct 30, 2019· Updated Jun 17, 2026
CVE-2018-21029
CVE-2018-21029
Description
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- systemd/systemddescription
cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:*range: >=239,<244
- (no CPE)range: 239 - 245
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- github.com/systemd/systemd/blob/v243/src/resolve/resolved-dnstls-gnutls.cnvdPatchThird Party Advisory
- github.com/systemd/systemd/pull/13870nvdPatchThird Party Advisory
- github.com/systemd/systemd/blob/v239/man/resolved.conf.xmlnvdExploitThird Party Advisory
- github.com/systemd/systemd/blob/v243/man/resolved.conf.xmlnvdExploitThird Party Advisory
- blog.cloudflare.com/dns-encryption-explained/nvdThird Party Advisory
- github.com/systemd/systemd/issues/9397nvdIssue TrackingThird Party Advisory
- security.netapp.com/advisory/ntap-20191122-0002/nvdThird Party Advisory
- tools.ietf.org/html/rfc7858nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NLJVOJMB6ANDILRLDZK26YGLYBEPHKY/nvd
News mentions
0No linked articles in our index yet.