Vulnerability record · CVE-2016-0742 · published 15 February 2016
CVE-2016-0742: nginx resolver NULL pointer dereference via crafted UDP DNS response
F5 · Nginx
The nginx resolver mishandles a crafted UDP DNS response, causing an invalid pointer dereference and a worker process crash. Because the resolver is used for upstream name resolution, a remote attacker who can influence DNS answers can take down nginx worker processes. The flaw affects nginx before 1.8.1 and 1.9.x before 1.9.10.
Description
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote, unauthenticated denial of service with a high EPSS score, though no KEV listing or documented ransomware use.
What it is
The nginx resolver mishandles a crafted UDP DNS response, causing an invalid pointer dereference and a worker process crash. Because the resolver is used for upstream name resolution, a remote attacker who can influence DNS answers can take down nginx worker processes. The flaw affects nginx before 1.8.1 and 1.9.x before 1.9.10.
Impact
An attacker gains denial of service: nginx worker processes crash, disrupting service for all requests handled by the affected workers. There is no confidentiality or integrity impact per the CVSS vector.
Attack surface
Reached remotely over the network by sending a crafted UDP DNS response to a resolver-enabled nginx instance; no authentication and no user interaction are required (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high (0.81958, 99.6th percentile), indicating elevated likelihood of exploitation activity; references include vendor and third-party advisories plus a patch-tagged bug report.
What to do
- Upgrade nginx to 1.8.1 or 1.9.10 or later, or apply the vendor patch referenced in the Red Hat bug report.
- Apply distribution-specific updates (Debian DSA-3473, Ubuntu USN-2892-1, Red Hat RHSA-2016:1425, openSUSE, Gentoo GLSA 201606-06).
- If the resolver feature is not required, disable it to remove the attack path.
- Restrict or monitor DNS traffic to nginx resolver endpoints so untrusted parties cannot inject crafted responses.
- Track vendor advisories for bundled nginx in products such as Xcode and Software Collections.
Detection
- Monitor nginx error logs for worker process crashes or resolver-related failures and correlate with DNS response activity.
- Alert on unexpected nginx worker restarts or core dumps on resolver-enabled hosts.
- Inspect DNS traffic to nginx resolver endpoints for malformed or anomalous UDP responses.
- Baseline resolver query volume and flag spikes consistent with crafted-response attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-0742 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-0742), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.