Home / Security / Advisories / NTAP-20180926-0005
NTAP-20180926-0005 — February 2018 ISC BIND Vulnerabilities in NetApp Products
Published 2018-09-26 · Updated 2020-09-01 · Status: Final · Exploitation: Public · Severity: HIGH 7.5 · ONTAP affected: Yes
Product family: ONTAP · SolidFire / NetApp HCI · Cloud Backup / AltaVault / SteelStore | ONTAP-relevant | highest CVSS: 7.5
CVEs in this advisory
- CVE-2016-2848 — HIGH · CVSS 7.5 · site index
- CVE-2016-8864 — HIGH · CVSS 7.5 · site index
- CVE-2016-9131 — HIGH · CVSS 7.5 · site index
- CVE-2016-9147 — HIGH · CVSS 7.5 · site index
- CVE-2016-9444 — HIGH · CVSS 7.5 · site index
- CVE-2016-9778 — HIGH · CVSS 7.5 · site index
- CVE-2017-3135 — HIGH · CVSS 7.5 · site index
- CVE-2018-5734 — HIGH · CVSS 7.5 · site index
What the CVE records say
CVE-2016-2848 — ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
CVE-2016-8864 — named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
CVE-2016-9131 — named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query.
CVE-2016-9147 — named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
CVE-2016-9444 — named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer.
CVE-2016-9778 — An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.
CVE-2017-3135 — Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1.
CVE-2018-5734 — While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND 9.10.5-S1 to 9.10.5-S4, 9.10.6-S1, 9.10.6-S2.
Impact
Successful exploitation of these vulnerabilities could lead to Denial of Service (DoS).
Affected products
- Data ONTAP Edge
- NetApp SolidFire & HCI Management Node
- NetApp SteelStore Cloud Integrated Storage
Official fixes
- NetApp SolidFire & HCI Management Node — vendor fix ↗
References
- https://kb.isc.org/article/AA-01433 ↗
- https://kb.isc.org/article/AA-01442/0 ↗
- https://kb.isc.org/article/AA-01453 ↗
- https://kb.isc.org/article/AA-01562/0/CVE-2018-5734 ↗
What to do
- Check the affected products listed above against the official advisory's affected-versions table — that is where the exact ONTAP 9 release, ONTAP tool, or management product versions are named.
- If affected and a fixed release exists, plan the upgrade — see the ONTAP upgrade runbook.
- If exploitation is listed as "active", treat remediation as urgent and review exposure (management LIFs, ONTAP S3, SnapMirror endpoints).
- Harden in parallel: security hardening baseline and ransomware protection on ONTAP.
Related reading
- Common ONTAP problems (FAQ) — plain-language symptoms and fixes
- ONTAP security hardening — baseline lockdown guidance
- Ransomware protection on ONTAP — SnapLock, SnapMirror vaulting, Anomaly Detection
- ONTAP error messages index — EMS/WAFL/NFS/SnapMirror messages
- Every NetApp advisory published in 2018