Unrated severityNVD Advisory· Published Jun 21, 2023· Updated Feb 13, 2025
Malformed NSEC records can cause named to terminate unexpectedly when synth-from-dnssec is enabled
CVE-2023-2829
Description
A named instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (synth-from-dnssec) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- kb.isc.org/docs/cve-2023-2829mitrevendor-advisory
- security.netapp.com/advisory/ntap-20230703-0010/mitre
News mentions
0No linked articles in our index yet.