Medium severity5.9NVD Advisory· Published Jan 16, 2019· Updated Jun 17, 2026
CVE-2018-5737
CVE-2018-5737
Description
A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-stale feature and NSEC aggressive negative caching can in some cases cause undesirable behavior from named, such as a recursion loop or excessive logging. Deliberate exploitation of this condition could cause operational problems depending on the particular manifestation -- either degradation or denial of service. Affects BIND 9.12.0 and 9.12.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
23- osv-coords17 versionspkg:apk/wolfi/bind-dnssec-rootpkg:apk/chainguard/bindpkg:apk/wolfi/bindpkg:apk/chainguard/bind-devpkg:apk/wolfi/bind-devpkg:apk/chainguard/bind-dnssec-rootpkg:apk/chainguard/bind-dnssec-toolspkg:apk/wolfi/bind-dnssec-toolspkg:apk/chainguard/bind-docpkg:apk/chainguard/bind-libspkg:apk/wolfi/bind-libspkg:apk/chainguard/bind-pluginspkg:apk/wolfi/bind-pluginspkg:apk/chainguard/bind-toolspkg:apk/wolfi/bind-toolspkg:apk/wolfi/bind-docpkg:rpm/opensuse/bind&distro=openSUSE%20Tumbleweed
< 0+ 16 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 9.16.20-1.4
- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- www.securityfocus.com/bid/104236nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1040942nvdThird Party AdvisoryVDB Entry
- kb.isc.org/docs/aa-01606nvdVendor Advisory
- security.netapp.com/advisory/ntap-20180926-0004/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.