]> git.ipfire.org Git - thirdparty/bind9.git/commitdiff
Add release note for [GL #4152]
authorMark Andrews <marka@isc.org>
Tue, 20 Jun 2023 05:38:40 +0000 (15:38 +1000)
committerMichal Nowak <mnowak@isc.org>
Thu, 7 Sep 2023 17:51:36 +0000 (19:51 +0200)
doc/notes/notes-current.rst

index 8bc1bb5561608d75641deed92f2cc68462072275..b01add6f215f3d0b53ba9fed56a63eb7a847405e 100644 (file)
@@ -15,7 +15,13 @@ Notes for BIND 9.18.19
 Security Fixes
 ~~~~~~~~~~~~~~
 
-- None.
+- Previously, sending a specially crafted message over the control
+  channel could cause the packet-parsing code to run out of available
+  stack memory, causing :iscman:`named` to terminate unexpectedly.
+  This has been fixed. (CVE-2023-3341)
+
+  ISC would like to thank Eric Sesterhenn from X41 D-Sec GmbH for
+  bringing this vulnerability to our attention. :gl:`#4152`
 
 New Features
 ~~~~~~~~~~~~