- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Jakub RužiÄka
- Date:
- 2022-07-09 10:45:06 UTC
- Severity:
- normal
- Tags:
[ Reason ] Fixing bug #991463 (CVE-2021-40083) - potential DoS. [ Impact ] Vulnerability to DoS attack. [ Tests ] I've tested the fix manually by running the deckard (DNS test harness) test sets/resolver/val_iter_high.rpl supplied with the upstream fix. It's not trivial to setup system for deckard so I've used upstream Debian bullseye docker image from Knot CI: docker run -it --privileged registry.nic.cz/knot/knot-resolver/ci/debian-11:knot-3.0 With current knot-resolver-5.3.1-1 the test failed. With suggested knot-resolver-5.3.1-1+deb11u1 the test passed. [ Risks ] This is a simple backport of upstream fix. Upstream tests run during package build so chances of something breaking are small. [ Checklist ] [*] *all* changes are documented in the d/changelog [*] I reviewed all changes and I approve them [*] attach debdiff against the package in (old)stable [*] the issue is verified as fixed in unstable [ Changes ] Backport of upstream fix for #991463: https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1169/diffs#c22c39e3a02cdfb0d3d47b16ff46e65d196df19d
Control: tag -1 confirmed Feel free to go ahead and upload, thank you. Cheers, Julien
[...] Ping? Regards, Adam
Hello, thanks for the ping, the previous mail got lost in my endless inbox and this bug isn't shown in the bug list available from knot-resolver package tracker so I completely lost track. Better late than never, I've uploaded knot-resolver_5.3.1-1+deb11u1 into proposed-updates. Cheers, Jakub Ružička 📦
package release.debian.org tags 993796 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: knot-resolver Version: 5.3.1-1+deb11u1 Explanation: fix possible assertion failure in NSEC3 edge-case [CVE-2021-40083]
package release.debian.org tags 993796 = bullseye pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian bullseye. Thanks for your contribution! Upload details ============== Package: knot-resolver Version: 5.3.1-1+deb11u1 Explanation: fix possible assertion failure in NSEC3 edge-case [CVE-2021-40083]
Hi, Each of the requests discussed in these bugs was included in today's bullseye point release. Regards, Adam