Add CHANGES and release note for [GL #3112]

This commit is contained in:
Ondřej Surý 2022-01-27 08:44:53 +01:00 committed by Michał Kępień
parent 6ec223a539
commit 4a025c19b9
2 changed files with 12 additions and 0 deletions

View file

@ -24,6 +24,13 @@
5821. [bug] Fix query context management issues in the TCP part
of dig. [GL #3184]
5818. [security] A synchronous call to closehandle_cb() caused
isc__nm_process_sock_buffer() to be called recursively,
which in turn left TCP connections hanging in the
CLOSE_WAIT state blocking indefinitely when
out-of-order processing was disabled. (CVE-2022-0396)
[GL #3112]
5817. [security] The rules for acceptance of records into the cache
have been tightened to prevent the possibility of
poisoning if forwarders send records outside

View file

@ -24,6 +24,11 @@ Security Fixes
Changgen Zou from Qi An Xin Group Corp. for bringing this
vulnerability to our attention. :gl:`#2950`
- TCP connections with ``keep-response-order`` enabled could leave the
TCP sockets in the ``CLOSE_WAIT`` state when the client did not
properly shut down the connection. (CVE-2022-0396) :gl:`#3112`
Known Issues
~~~~~~~~~~~~