CVE-2021-23017
published 2021-06-01CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory…
PriorityP272high7.7CVSS 3.1
AVNACHPRNUINSUCHIHAL
EXPLOIT
EPSS
53.46%
98.9th percentile
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | < nginx 1.18.0-6.1 (bookworm) | nginx 1.18.0-6.1 (bookworm) |
| f5 | nginx | — | — |
| f5 | nginx | >= 0 < 1.18.0-6.1 | 1.18.0-6.1 |
| f5 | nginx | >= 0 < 1.18.0-6.1 | 1.18.0-6.1 |
| f5 | nginx | >= 0 < 1.18.0-6.1 | 1.18.0-6.1 |
| f5 | nginx | >= 0 < 1.18.0-6.1 | 1.18.0-6.1 |
| f5 | nginx | >= 0.6.18 < 1.20.1 | 1.20.1 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cm1_nginx_1.20.1-1_on_cbl_mariner_1.0 | — | — |
| openresty | openresty | < 1.19.3.2 | 1.19.3.2 |
| oracle | blockchain_platform | < 21.1.2 | 21.1.2 |
| oracle | communications_control_plane_monitor | — | — |
| oracle | communications_control_plane_monitor | — | — |
| oracle | communications_control_plane_monitor | — | — |
| oracle | communications_control_plane_monitor | — | — |
| oracle | communications_fraud_monitor | 3.4 – 4.4 | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_operations_monitor | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | communications_session_border_controller | — | — |
| oracle | enterprise_communications_broker | — | — |
| oracle | enterprise_session_border_controller | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x81\x80\x00\x01\x00\x01\x00\x00\x00\x00
bytes↗
\xC0\x0C\x00\x05\x00\x01\x00\x00\x0E\x10
bytes↗
\x00\x0B\x18\x41\x41\x41\x41\x41\x41\x41
- →The exploit requires ARP poisoning to intercept DNS UDP traffic between the nginx worker and its configured DNS resolver, then injects a crafted DNS response with a malicious CNAME pointer (\xC0\x04) to trigger a 1-byte memory overwrite. Detect ARP spoofing on the network segment hosting the nginx resolver. ↗
- →The attack forges UDP packets from the DNS server port 53 toward the nginx worker. Monitor for spoofed UDP/53 responses containing oversized or malformed CNAME records with compressed pointer offsets (\xC0\x0C, \xC0\x04) and large label lengths (\x18 = 24 bytes) in DNS answers. ↗
- →The exploit drops forwarded UDP/53 packets via iptables to prevent legitimate DNS responses from reaching nginx, ensuring only the crafted response is processed. Detect unexpected iptables FORWARD DROP rules on UDP port 53 on hosts in the network path. ↗
- →Vulnerability affects nginx versions 0.6.18 through 1.20.0 (and up to 1.20.1 per F5 advisory) when the resolver directive is configured. Audit nginx configurations for active resolver directives and prioritize patching instances in that version range. ↗
- →The vulnerability is only exploitable when nginx is configured to use a DNS resolver. Identify and monitor all nginx deployments with the 'resolver' directive enabled as the attack surface. ↗
- ·The vulnerability is only exploitable when nginx has a resolver directive configured. Deployments without a resolver directive are not affected. ↗
- ·The attacker must be able to forge UDP packets from the DNS server (e.g., via ARP poisoning or network-level MITM), meaning the attack is most feasible from within the same network segment as the nginx resolver. ↗
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.7HIGH
vendor_oracle9.8HIGH
vendor_debian7.7HIGH
vendor_msrc7.7HIGH
vendor_redhat7.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (nginx) — CVE-2021-23017
vendor_oracle·2023-04-15·CVSS 7.7
CVE-2021-23017 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (nginx) — CVE-2021-23017
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (nginx) vulnerability
CVE: CVE-2021-23017
CVSS: 7.7
Protocol: UDP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: Backend (nginx) — CVE-2021-23017
vendor_oracle·2022-04-15·CVSS 9.8
CVE-2021-23017 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: Backend (nginx) — CVE-2021-23017
Oracle Oracle Blockchain Platform Risk Matrix: Backend (nginx) vulnerability
CVE: CVE-2021-23017
CVSS: 9.8
Protocol: UDP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle GoldenGate Risk Matrix: GG Market Place for Support (nginx) — CVE-2021-23017
vendor_oracle·2022-01-15·CVSS 9.4
CVE-2021-23017 [HIGH] Oracle Oracle GoldenGate Risk Matrix: GG Market Place for Support (nginx) — CVE-2021-23017
Oracle Oracle GoldenGate Risk Matrix: GG Market Place for Support (nginx) vulnerability
CVE: CVE-2021-23017
CVSS: 9.4
Protocol: UDP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Risk Matrix: Infrastructure (nginx) — CVE-2021-23017
vendor_oracle·2021-10-15·CVSS 9.4
CVE-2021-23017 [HIGH] Oracle Oracle Communications Risk Matrix: Infrastructure (nginx) — CVE-2021-23017
Oracle Oracle Communications Risk Matrix: Infrastructure (nginx) vulnerability
CVE: CVE-2021-23017
CVSS: 9.4
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Microsoft
A security issue in nginx resolver was identified which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite resulting in worker process crash
vendor_msrc·2021-06-08·CVSS 7.7
CVE-2021-23017 [HIGH] CWE-193 A security issue in nginx resolver was identified which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite resulting in worker process crash
A security issue in nginx resolver was identified which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite resulting in worker process crash or potential other impact.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is iden
F5
CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets fro...
vendor_f5·2021-06-01·CVSS 7.7
CVE-2021-23017 [HIGH] CWE-193 CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets fro...
CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets fro...
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Affected Products: NGINX
Affected Versions: 0.6.18 - 1.20.1
F5 Advisory Articles: K12331123
F5 References: https://support.f5.com/csp/article/K12331123%2C
Ubuntu
nginx vulnerability
vendor_ubuntu·2021-05-27
CVE-2021-23017 nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to crash or run programs if it received specially
crafted network traffic.
USN-4967-1 fixed a vulnerability in nginx. This update provides
the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.
Original advisory details:
Luis Merino, Markus Vervier, and Eric Sesterhenn discovered that nginx
incorrectly handled responses to the DNS resolver. A remote attacker could
use this issue to cause nginx to crash, resulting in a denial of service,
or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
nginx vulnerability
vendor_ubuntu·2021-05-26
CVE-2021-23017 nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to crash or run programs if it received specially
crafted network traffic.
Luis Merino, Markus Vervier, and Eric Sesterhenn discovered that nginx
incorrectly handled responses to the DNS resolver. A remote attacker could
use this issue to cause nginx to crash, resulting in a denial of service,
or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name
vendor_redhat·2021-05-25·CVSS 7.7
CVE-2021-23017 [HIGH] CWE-193 nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name
nginx: Off-by-one in ngx_resolver_copy() when labels are followed by a pointer to a root domain name
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
A flaw was found in nginx. An off-by-one error while processing DNS responses allows a network attacker to write a dot character out of bounds in a heap allocated buffer which can allow overwriting the least significant byte of next heap chunk metadata likely leading to a remote code execution in certain circumstances. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: nginx:1.14/nginx (Red
Debian
CVE-2021-23017: nginx - A security issue in nginx resolver was identified, which might allow an attacker...
vendor_debian·2021·CVSS 7.7
CVE-2021-23017 [HIGH] CVE-2021-23017: nginx - A security issue in nginx resolver was identified, which might allow an attacker...
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Scope: local
bookworm: resolved (fixed in 1.18.0-6.1)
bullseye: resolved (fixed in 1.18.0-6.1)
forky: resolved (fixed in 1.18.0-6.1)
sid: resolved (fixed in 1.18.0-6.1)
trixie: resolved (fixed in 1.18.0-6.1)
GHSA
GHSA-83p9-mcpm-374v: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte
ghsa_unreviewed·2022-05-24
CVE-2021-23017 [CRITICAL] CWE-193 GHSA-83p9-mcpm-374v: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
OSV
CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte
osv·2021-06-01·CVSS 7.7
CVE-2021-23017 [HIGH] CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
No detection rules found.
HackerOne
1-byte heap buffer overflow in DNS resolver
hackerone·2021-08-27·CVSS 7.7
CVE-2021-23017 [HIGH] 1-byte heap buffer overflow in DNS resolver
1-byte heap buffer overflow in DNS resolver
Official announcement: http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html
A security issue in nginx resolver was identified, which might allow an
attacker to cause 1-byte memory overwrite by using a specially crafted
DNS response, resulting in worker process crash or, potentially, in
arbitrary code execution (CVE-2021-23017).
The issue only affects nginx if the "resolver" directive is used in
the configuration file. Further, the attack is only possible if an
attacker is able to forge UDP packets from the DNS server.
The issue affects nginx 0.6.18 - 1.20.0.
The issue is fixed in nginx 1.21.0, 1.20.1.
Patch for the issue can be found here:
http://nginx.org/download/patch.2021.resolver.txt
Thanks to Luis Merino, Markus Vervier
arXiv
ZeroDayBench: Evaluating LLM Agents on Unseen Zero-Day Vulnerabilities for Cyberdefense
arxiv_fulltext·2026-03-02
ZeroDayBench: Evaluating LLM Agents on Unseen Zero-Day Vulnerabilities for Cyberdefense
## Abstract
Large language models (LLMs) are increasingly being deployed as software engineering agents that autonomously contribute to repositories. A major benefit these agents present is their ability to find and patch security vulnerabilities in the codebases they oversee. To estimate the capability of agents in this domain, we introduce ZeroDayBench, a benchmark where LLM agents find and patch 22 novel critical vulnerabilities in open-source codebases. We focus our efforts on three popular frontier agentic LLMs: GPT-5.2, Claude Sonnet 4.5, and Grok 4.1. We find that frontier LLMs are not yet capable of autonomously solving our tasks and observe some behavioral patterns that suggest how these models can be improved in the domain of proactive cyberdefense.
## Introduction
Large langu
http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.htmlhttp://packetstormsecurity.com/files/167720/Nginx-1.20.0-Denial-Of-Service.htmlhttps://lists.apache.org/thread.html/r37e6b2165f7c910d8e15fd54f4697857619ad2625f56583802004009%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/r4d4966221ca399ce948ef34884652265729d7d9ef8179c78d7f17e7f%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/r6fc5c57b38e93e36213e9a18c8a4e5dbd5ced1c7e57f08a1735975ba%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/rf232eecd47fdc44520192810560303073cefd684b321f85e311bad31%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/rf318aeeb4d7a3a312734780b47de83cefb7e6995da0b2cae5c28675c%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SFVYHC7OXTEO4SMBWXDVK6E5IMEYMEE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GNKOP2JR5L7KCIZTJRZDCUPJTUONMC5I/https://security.netapp.com/advisory/ntap-20210708-0006/https://support.f5.com/csp/article/K12331123%2Chttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2021/000300.htmlhttp://packetstormsecurity.com/files/167720/Nginx-1.20.0-Denial-Of-Service.htmlhttps://lists.apache.org/thread.html/r37e6b2165f7c910d8e15fd54f4697857619ad2625f56583802004009%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/r4d4966221ca399ce948ef34884652265729d7d9ef8179c78d7f17e7f%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/r6fc5c57b38e93e36213e9a18c8a4e5dbd5ced1c7e57f08a1735975ba%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/rf232eecd47fdc44520192810560303073cefd684b321f85e311bad31%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.apache.org/thread.html/rf318aeeb4d7a3a312734780b47de83cefb7e6995da0b2cae5c28675c%40%3Cnotifications.apisix.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7SFVYHC7OXTEO4SMBWXDVK6E5IMEYMEE/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GNKOP2JR5L7KCIZTJRZDCUPJTUONMC5I/https://security.netapp.com/advisory/ntap-20210708-0006/https://support.f5.com/csp/article/K12331123%2Chttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-01
Published