PT-2019-15812 · Cz.Nic+2 · Knot Resolver+2
Published
2019-12-16
·
Updated
2024-10-01
·
CVE-2019-19331
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
knot-resolver versions prior to 4.3.0
Description
The issue allows for denial of service through high CPU utilization. This occurs when DNS replies contain a large number of resource records, which can be processed inefficiently. In extreme cases, processing a single uncached message can take several CPU seconds. For example, a DNS message can contain a few thousand A records, with a limit of 64kB.
Recommendations
For versions prior to 4.3.0, update to version 4.3.0 or later to resolve the issue. As a temporary workaround, consider restricting the size of DNS messages or limiting the number of resource records processed to minimize the risk of high CPU utilization.
Exploit
Fix
DoS
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Knot Resolver