Vulnerability record · CVE-2017-9445 · published 28 June 2017
CVE-2017-9445: systemd-resolved DNS response buffer overflow
Systemd Project · Systemd
systemd-resolved through version 233 passes certain sizes to dns_packet_new that can cause allocation of a buffer that is too small. A malicious DNS server can send a specially crafted TCP response to trigger an out-of-bounds write beyond the allocated buffer.
Description
In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 with network reachability and no authentication or user interaction, plus very high EPSS, makes this a serious remote denial-of-service and potential code execution risk.
What it is
systemd-resolved through version 233 passes certain sizes to dns_packet_new that can cause allocation of a buffer that is too small. A malicious DNS server can send a specially crafted TCP response to trigger an out-of-bounds write beyond the allocated buffer.
Impact
An attacker controlling a DNS server can corrupt memory in systemd-resolved, leading to a crash or denial of service and potentially arbitrary code execution in the context of the resolver process.
Attack surface
Reachable over the network via DNS responses; the CVSS vector shows AV:N/PR:N/UI:N, so no authentication or user interaction is required, but the victim must resolve a name through the malicious DNS server.
Exploitation
Not listed in CISA KEV, but EPSS is 0.54837 (99th percentile), indicating a high modeled likelihood of exploitation; references include a patch and third-party advisories.
What to do
- Update systemd to a version after 233 that includes the dns_packet_new fix.
- Apply the patch referenced in the oss-security advisory if a full upgrade is not immediately possible.
- Restrict systemd-resolved to trusted DNS servers and avoid untrusted or attacker-controlled resolvers.
- Monitor vendor advisories for backported fixes in your distribution.
Detection
- Monitor systemd-resolved logs for crashes, restarts, or abnormal termination.
- Inspect DNS traffic for unusually large or malformed TCP responses to systemd-resolved.
- Track host-level memory corruption indicators or core dumps from systemd-resolved.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://openwall.com/lists/oss-security/2017/06/27/8 | Mailing ListPatchThird Party Advisory |
| http://www.securityfocus.com/bid/99302 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038806 | Third Party AdvisoryVDB Entry |
| https://launchpad.net/bugs/1695546 | Broken Link |
| http://openwall.com/lists/oss-security/2017/06/27/8 | Mailing ListPatchThird Party Advisory |
| http://www.securityfocus.com/bid/99302 | Third Party AdvisoryVDB Entry |
| http://www.securitytracker.com/id/1038806 | Third Party AdvisoryVDB Entry |
| https://launchpad.net/bugs/1695546 | Broken Link |
Track CVE-2017-9445 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9445), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.