Candidate: CVE-2017-9217 PublicDate: 2017-05-24 05:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9217 https://github.com/systemd/systemd/pull/5998 https://github.com/systemd/systemd/pull/6020 Description: systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS response with an empty question section. Ubuntu-Description: Notes: tyhicks> I believe that this was introduced in v223 by https://github.com/systemd/systemd/commit/29815b6c608b836cada5e349d06a96b63eaa65f3 tyhicks> Lennart pointed out in the pull request that systemd-resolved is respawned after crashing. Therefore, I've rated this as a low priority. tyhicks> systemd-resolved became the default DNS resolver in Zesty and it is enabled in Yakkety tyhicks> systemd-resolved is not used by default in Xenial. It is spawned if a user execs the systemd-resolve utility but that shouldn't impact the system. Bugs: https://launchpad.net/bugs/1621396 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_systemd: upstream: https://github.com/systemd/systemd/commit/a924f43f30f9c4acaf70618dd2a055f8b0f166be upstream_systemd: needed precise/esm_systemd: DNE trusty_systemd: not-affected (204-5ubuntu20.24) trusty/esm_systemd: not-affected (204-5ubuntu20.24) vivid/stable-phone-overlay_systemd: not-affected (219-7ubuntu6vividtouch1) vivid/ubuntu-core_systemd: not-affected (219-7ubuntu6) Priority_systemd_xenial: negligible xenial_systemd: released (229-4ubuntu19) esm-infra/xenial_systemd: released (229-4ubuntu19) yakkety_systemd: ignored (reached end-of-life) zesty_systemd: released (232-21ubuntu4) devel_systemd: released (233-6ubuntu3)