CVE-2018-21029
published 2019-10-30CVE-2018-21029: systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there…
PriorityP348critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.14%
86.4th percentile
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | systemd | < systemd 244-1 (bookworm) | systemd 244-1 (bookworm) |
| fedoraproject | fedora | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_systemd_239-31_on_cbl_mariner_1.0 | — | — |
| systemd_project | systemd | >= 0 < 244-1 | 244-1 |
| systemd_project | systemd | >= 0 < 244-1 | 244-1 |
| systemd_project | systemd | >= 0 < 244-1 | 244-1 |
| systemd_project | systemd | >= 0 < 244-1 | 244-1 |
| systemd_project | systemd | >= 239 < 244 | 244 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_msrc9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent and there is no hostname validation with the GnuTLS
vendor_msrc·2019-10-08·CVSS 9.8
CVE-2018-21029 [CRITICAL] CWE-295 systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent and there is no hostname validation with the GnuTLS
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to tran
Red Hat
systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS
vendor_redhat·2018-06-24·CVSS 9.8
CVE-2018-21029 [CRITICAL] CWE-295 systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS
systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
A flaw in systemd-resolved was found to incorrectly verify certificates of a DNS resolver used for DNS Over TLS when the DNSOverTLS option is set to `yes`. A remote attacker in the network path between the vulnerable system and the DNS resolver may use this flaw to
Debian
CVE-2018-21029: systemd - systemd 239 through 245 accepts any certificate signed by a trusted certificate ...
vendor_debian·2018·CVSS 9.8
CVE-2018-21029 [CRITICAL] CVE-2018-21029: systemd - systemd 239 through 245 accepts any certificate signed by a trusted certificate ...
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
Scope: local
bookworm: resolved (fixed in 244-1)
bullseye: resolved (fixed in 244-1)
forky: resolved (fixed in 244-1)
sid: resolved (fixed in 244-1)
trixie: resolved (fixed in 244-1)
GHSA
GHSA-h2fw-qh29-9jv7: systemd 239 through 243 accepts any certificate signed by a trusted certificate authority for DNS Over TLS
ghsa_unreviewed·2022-05-24
CVE-2018-21029 [CRITICAL] CWE-295 GHSA-h2fw-qh29-9jv7: systemd 239 through 243 accepts any certificate signed by a trusted certificate authority for DNS Over TLS
systemd 239 through 243 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend.
OSV
CVE-2018-21029: systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS
osv·2019-10-30·CVSS 9.8
CVE-2018-21029 [CRITICAL] CVE-2018-21029: systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS
systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-21029 systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS [fedora-all]
bugzilla·2019-11-12·CVSS 9.8
CVE-2018-21029 [CRITICAL] CVE-2018-21029 systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS [fedora-all]
CVE-2018-21029 systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM ch
Bugzilla
CVE-2018-21029 systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS
bugzilla·2019-11-12·CVSS 9.8
CVE-2018-21029 [CRITICAL] CVE-2018-21029 systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS
CVE-2018-21029 systemd: incorrect certificate validation results in acceptance of any certificate signed by a trusted certificate authority for DNS over TLS
systemd 239 through 243 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend.
Reference:
https://github.com/systemd/systemd/issues/9397
Discussion:
Created systemd tracking bugs for this issue:
Affects: fedora-all [bug 1771726]
---
Since version 239, systemd supports DNSOverTLS, however from v239 to v242 only `opportunistic` mode is implemented and the man page resolved.conf explicitly explain the limitation of the implementation, by saying `Note as the resolver is not capable of authenticating the
https://blog.cloudflare.com/dns-encryption-explained/https://github.com/systemd/systemd/blob/v239/man/resolved.conf.xml#L199-L207https://github.com/systemd/systemd/blob/v243/man/resolved.conf.xml#L196-L207https://github.com/systemd/systemd/blob/v243/src/resolve/resolved-dnstls-gnutls.c#L62-L63https://github.com/systemd/systemd/issues/9397https://github.com/systemd/systemd/pull/13870https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NLJVOJMB6ANDILRLDZK26YGLYBEPHKY/https://security.netapp.com/advisory/ntap-20191122-0002/https://tools.ietf.org/html/rfc7858#section-4.1https://blog.cloudflare.com/dns-encryption-explained/https://github.com/systemd/systemd/blob/v239/man/resolved.conf.xml#L199-L207https://github.com/systemd/systemd/blob/v243/man/resolved.conf.xml#L196-L207https://github.com/systemd/systemd/blob/v243/src/resolve/resolved-dnstls-gnutls.c#L62-L63https://github.com/systemd/systemd/issues/9397https://github.com/systemd/systemd/pull/13870https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NLJVOJMB6ANDILRLDZK26YGLYBEPHKY/https://security.netapp.com/advisory/ntap-20191122-0002/https://tools.ietf.org/html/rfc7858#section-4.1
2019-10-30
Published