Code review comment for ~rafaeldtinoco/ubuntu/+source/bind9:eoan-bind9-merge

Revision history for this message
Andreas Hasenack (ahasenack) wrote :

Ping #security to see if they have a patch ready for that for eoan. It was pushed to -security just a few days ago for other releases:
bind9 (1:9.11.3+dfsg-1ubuntu1.8) bionic-security; urgency=medium

  * SECURITY UPDATE: DoS via malformed packets
    - debian/patches/CVE-2019-6471.patch: fix race condition in
      lib/dns/dispatch.c.
    - CVE-2019-6471

 -- Marc Deslauriers <email address hidden> Tue, 18 Jun 2019 18:55:08 -0400

The secteam not always pushed it to the devel release, but they eventually take care of it. If the patch is ready, or maybe even if that one above can be cherry-picked, you could add it now on top of the merge.

« Back to merge proposal