CVE-2017-15908 describes a denial-of-service vulnerability in systemd-resolved, affecting systemd versions 223 through 235, including Canonical Ubuntu Linux. A remote DNS server can trigger an infinite loop by sending a specially crafted DNS NSEC resource record, leading to a DoS of the affected service. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, resulting in high availability impact. There is no known active exploitation, publicly available exploit code, or Metasploit/Nuclei modules, though it has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
223CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:223:*:*:*:*:*:*:* | ||
224CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:224:*:*:*:*:*:*:* | ||
225CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:225:*:*:*:*:*:*:* | ||
226CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:226:*:*:*:*:*:*:* | ||
227CPE matchmatch criteria | cpe:2.3:a:systemd_project:systemd:227:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.