Bug 1216479 (CVE-2023-46317) - VUL-0: CVE-2023-46317: knot-resolver: performs many TCP reconnections upon receiving certain nonsensical responses from servers.
Summary: VUL-0: CVE-2023-46317: knot-resolver: performs many TCP reconnections upon re...
Status: RESOLVED INVALID
Alias: CVE-2023-46317
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P5 - None : Normal (vote)
Target Milestone: ---
Assignee: Michal Hrusecky
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/382716/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-10-23 07:32 UTC by SMASH SMASH
Modified: 2023-10-23 07:42 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-10-23 07:32:27 UTC
Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-46317
https://www.knot-resolver.cz/2023-08-22-knot-resolver-5.7.0.html
https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1448
Comment 1 Robert Frohl 2023-10-23 07:42:18 UTC
not relevant for knot
Comment 2 Robert Frohl 2023-10-23 07:42:40 UTC
knot-resolver not part of any distro