Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Fedora 28 FEDORA-2018-389bc4e911 Moderate Knot Resolver Denial Of Service

fedora
Calendar Grey May 9, 2018
Dist Fedora Esm H88
The latest Knot Resolver 2.3.0 release for Fedora mitigates denial of service vulnerabilities and boosts defense mechanisms against potential threats.
Knot Resolver 2.3.0 (2018-04-23) -------- - fix CVE-2018-1110: denial of service triggered by malformed DNS messages (!550, !558, security!2, security!4) - increase resilience aga...

Summary

The Knot DNS Resolver is a caching full resolver implementation written in C

and LuaJIT, including both a resolver library and a daemon. Modular

architecture of the library keeps the core tiny and efficient, and provides

a state-machine like API for extensions.

The package is pre-configured as local caching resolver.

To start using it, start a single kresd instance:

$ systemctl start kresd@1.service

Knot Resolver 2.3.0 (2018-04-23) ================================ Security

-------- - fix CVE-2018-1110: denial of service triggered by malformed DNS

messages (!550, !558, security!2, security!4) - increase resilience against

slow lorris attack (security!5) Bugfixes -------- - validation: fix SERVFAIL in

case of CNAME to NXDOMAIN in a single zone (!538) - validation: fix SERVFAIL for

DS . query (!544) - lib/resolve: don't send unecessary queries to parent zone

(!513) - iterate: fix validation for zones where parent and child share NS

(!543) - TLS: improve error handling and documentation (!536, !555, !559)

Improvements ------------ - prefill: new module to periodically import root zone

into cache (replacement for RFC 7706, !511) - network_listen_fd: always create

end point for supervisor supplied file descriptor - use CPPFLAGS build

environment variable if set (!547)

* Mon Apr 23 2018 Tomas Krizek - 2.3.0-1

Knot Resolver 2.3.0 (2018-04-23)

===============================

Security

--------- fix CVE-2018-1110: denial of service triggered by malformed DNS messages

(!550, !558, security!2, security!4)

- increase resilience against slow lorris attack (security!5)

Bugfixes

--------- validation: fix SERVFAIL in case of CNAME to NXDOMAIN in a single zone (!538)

- validation: fix SERVFAIL for DS . query (!544)

- lib/resolve: don't send unecessary queries to parent zone (!513)

- iterate: fix validation for zones where parent and child share NS (!543)

- TLS: improve error handling and documentation (!536, !555, !559)

Improvements

------------- prefill: new module to periodically import root zone into cache

(replacement for RFC 7706, !511)

- network_listen_fd: always create end point for supervisor supplied file descriptor

- use CPPFLAGS build environment variable if set (!547)

su -c 'dnf upgrade --advisory FEDORA-2018-389bc4e911' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 28
Version: 2.3.0
Release: 1.fc28
Summary: Caching full DNS Resolver

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here