CVE-2022-37428: PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties. Please bump to 4.7.2.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8fbf54bc21dd4b5c777be76a031350782ced07e8 commit 8fbf54bc21dd4b5c777be76a031350782ced07e8 Author: Sven Wegener <swegener@gentoo.org> AuthorDate: 2022-08-23 20:37:55 +0000 Commit: Sven Wegener <swegener@gentoo.org> CommitDate: 2022-08-23 20:49:24 +0000 net-dns/pdns-recursor: Version bump, security bug #866219 Bug: https://bugs.gentoo.org/866219 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Sven Wegener <swegener@gentoo.org> net-dns/pdns-recursor/Manifest | 1 + net-dns/pdns-recursor/pdns-recursor-4.7.2.ebuild | 88 ++++++++++++++++++++++++ 2 files changed, 89 insertions(+)
Thanks! Please stabilize when ready.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e19ba0ba9fb02db215a2c923716fa358dd618ff0 commit e19ba0ba9fb02db215a2c923716fa358dd618ff0 Author: Sven Wegener <swegener@gentoo.org> AuthorDate: 2022-08-23 21:04:47 +0000 Commit: Sven Wegener <swegener@gentoo.org> CommitDate: 2022-08-23 21:05:02 +0000 net-dns/pdns-recursor: Stabilize 4.7.2 on amd64/x86, sec. bug #866219 Bug: https://bugs.gentoo.org/866219 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Sven Wegener <swegener@gentoo.org> net-dns/pdns-recursor/pdns-recursor-4.7.2.ebuild | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
Thanks! Please cleanup.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=624fc1897cd287ccce57884edf8d3b8391bcc1f6 commit 624fc1897cd287ccce57884edf8d3b8391bcc1f6 Author: Sven Wegener <swegener@gentoo.org> AuthorDate: 2022-08-24 16:35:26 +0000 Commit: Sven Wegener <swegener@gentoo.org> CommitDate: 2022-08-24 16:36:41 +0000 net-dns/pdns-recursor: Cleanup Bug: https://bugs.gentoo.org/866219 Package-Manager: Portage-3.0.30, Repoman-3.0.3 Signed-off-by: Sven Wegener <swegener@gentoo.org> net-dns/pdns-recursor/Manifest | 1 - net-dns/pdns-recursor/pdns-recursor-4.7.1.ebuild | 88 ------------------------ 2 files changed, 89 deletions(-)