CVE-2017-9445
published 2017-06-28CVE-2017-9445: In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server…
PriorityP359high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
55.12%
98.9th percentile
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 233-10 (bookworm) | systemd 233-10 (bookworm) |
| systemd_project | systemd | >= 0 < 233-10 | 233-10 |
| systemd_project | systemd | >= 0 < 233-10 | 233-10 |
| systemd_project | systemd | >= 0 < 233-10 | 233-10 |
| systemd_project | systemd | >= 0 < 233-10 | 233-10 |
| systemd_project | systemd | 223 – 233 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via a specially crafted DNS response over TCP; monitor for anomalous or oversized DNS TCP payloads sent to hosts running systemd-resolved. ↗
- →The vulnerable function is dns_packet_new in systemd-resolved; crash or unexpected termination of the systemd-resolved daemon process may indicate exploitation attempts. ↗
- →Exploitation can result in daemon crash or arbitrary code execution in the context of the systemd-resolved process; alert on unexpected crashes or restarts of systemd-resolved. ↗
- ·Red Hat Enterprise Linux 7 ships a version of systemd that is NOT affected by this CVE; detection efforts should focus on other distributions (e.g., Ubuntu, Fedora, Debian) running systemd through version 233. ↗
- ·The vulnerability is fixed in systemd 233-10 on Debian-based systems; ensure patched versions are deployed before deprioritizing detection coverage. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Systemd vulnerability
vendor_ubuntu·2017-06-27·CVSS 7.5
CVE-2017-9445 [HIGH] Systemd vulnerability
Title: Systemd vulnerability
Summary: systemd-resolved could be made to crash or run programs if it received
a specially crafted DNS response.
An out-of-bounds write was discovered in systemd-resolved when handling
specially crafted DNS responses. A remote attacker could potentially
exploit this to cause a denial of service (daemon crash) or execute
arbitrary code. (CVE-2017-9445)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new
vendor_redhat·2017-06-27·CVSS 7.5
CVE-2017-9445 [HIGH] CWE-787 systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new
systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
An out-of-bounds write flaw was found in the way systemd-resolved daemon handled processing of DNS responses. A remote attacker could potentially use this flaw to crash the daemon or execute arbitrary code in the context of the daemon process.
Statement: This issue did not affect the versions of systemd as shipped with Red Hat Enterprise
Debian
CVE-2017-9445: systemd - In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolv...
vendor_debian·2017·CVSS 7.5
CVE-2017-9445 [HIGH] CVE-2017-9445: systemd - In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolv...
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
Scope: local
bookworm: resolved (fixed in 233-10)
bullseye: resolved (fixed in 233-10)
forky: resolved (fixed in 233-10)
sid: resolved (fixed in 233-10)
trixie: resolved (fixed in 233-10)
GHSA
GHSA-42xm-66qf-5jj8: In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small
ghsa_unreviewed·2022-05-13
CVE-2017-9445 [HIGH] CWE-787 GHSA-42xm-66qf-5jj8: In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
OSV
CVE-2017-9445: In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small
osv·2017-06-28·CVSS 7.5
CVE-2017-9445 [HIGH] CVE-2017-9445: In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-9445 systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new [fedora-all]
bugzilla·2017-06-28·CVSS 7.5
CVE-2017-9445 [HIGH] CVE-2017-9445 systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new [fedora-all]
CVE-2017-9445 systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2017-9445 systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new
bugzilla·2017-06-21·CVSS 7.5
CVE-2017-9445 [HIGH] CVE-2017-9445 systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new
CVE-2017-9445 systemd: Out-of-bounds write in systemd-resolved due to allocating too small buffer in dns_packet_new
An out-of-bounds write in systemd-resolved due to allocating buffer that is too small in dns_packet_new was found. Malicious DNS server can exploit this by responding with specially crafted TCP payload to write arbitrary data beyond the allocated buffer.
Discussion:
Acknowledgments:
Name: Chris Coulson (Canonical)
---
Created attachment 1290017
Proposed patch
---
Statement:
This issue did not affect the versions of systemd as shipped with Red Hat Enterprise Linux 7.
---
Created systemd tracking bugs for this issue:
Affects: fedora-all [bug 1465728]
---
References:
http://seclists.org/oss-sec/2017/q2/618
http://openwall.com/lists/oss-security/2017/06/27/8http://www.securityfocus.com/bid/99302http://www.securitytracker.com/id/1038806https://launchpad.net/bugs/1695546http://openwall.com/lists/oss-security/2017/06/27/8http://www.securityfocus.com/bid/99302http://www.securitytracker.com/id/1038806https://launchpad.net/bugs/1695546
2017-06-28
Published