Add CHANGES and release notes for [GL #3619]

(cherry picked from commit d08a478b42)
This commit is contained in:
Aram Sargsyan 2022-11-14 12:30:49 +00:00 committed by Michał Kępień
parent a4fc5e5158
commit 601066e854
2 changed files with 12 additions and 0 deletions

View file

@ -1,3 +1,6 @@
6067. [security] Fix serve-stale crash when recursive clients soft quota
is reached. (CVE-2022-3924) [GL #3619]
6066. [security] Handle RRSIG lookups when serve-stale is active.
(CVE-2022-3736) [GL #3622]

View file

@ -32,6 +32,15 @@ Security Fixes
Iratxe Niño from Fundación Sarenet) for bringing this vulnerability to
our attention. :gl:`#3622`
- :iscman:`named` running as a resolver with the
:any:`stale-answer-client-timeout` option set to any value greater
than ``0`` could crash with an assertion failure, when the
:any:`recursive-clients` soft quota was reached. This has been fixed.
(CVE-2022-3924)
ISC would like to thank Maksym Odinintsev from AWS for bringing this
vulnerability to our attention. :gl:`#3619`
New Features
~~~~~~~~~~~~