---
title: "CVE-2021-23017"
canonical: "https://kb.cynergy.app/space/MD/899285395/CVE-2021-23017"
format: markdown
---
**Description:**

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

**Published On:**

2021-05-25

**CVSS 3.1 Score:**

Base Score 9.4

Impact Score 5.451

Exploitability Score: 3.887

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

**Exploit**

nginx 1.20.0 DNS Resolver Off-By-One Heap Write

**Resource**:

[https://packetstormsecurity.com/files/162830/nginx-1.20.0-DNS-Resolver-Off-By-One-Heap-Write.html](https://packetstormsecurity.com/files/162830/nginx-1.20.0-DNS-Resolver-Off-By-One-Heap-Write.html) 

**Trending:**

False

**CWE-193**

**Mitigation:**

![image](media://eb46672d-60a5-428e-957b-a9ad4cafdf3f)

Cynergy has an automated mitigation capability that requires integration with your WAF provider. 

Once integrated, you can request “Protect with WAF” 

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately </span>

**Remediation:**

Update based on the vendor recommendations:

|  |  |  |  |  |  |
| --- | --- | --- | --- | --- | --- |
| Patch Id | Vendor | Fix Title | Fix Description | Fix Published On | Fix URL |
| RHSA-2021:2290 | OpenSource | nginx-1.16.1-2.module+el8.4.0+11155+68135136.1 | An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.1 Extended Update Support, and Red Hat Enterprise Linux 8.2 Extended Update Support.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2021:2290](https://access.redhat.com/errata/RHSA-2021:2290) |
| RHSA-2021:2259 | OpenSource | nginx-1.18.0-3.module+el8.4.0+11152+f736ed63.1 | An update for the nginx:1.18 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2021:2259](https://access.redhat.com/errata/RHSA-2021:2259) |
| RHSA-2022:0323 | OpenSource | nginx-1.20.1-1.module+el8.5.0+13723+ab304644 | An update for the nginx:1.20 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2022-04-24 | [https://access.redhat.com/errata/RHSA-2022:0323](https://access.redhat.com/errata/RHSA-2022:0323) |
| RHBA-2021:2955 | redhat | Red Hat Bug Fix Advisory: Red Hat Automation Platform 1.2.4 | An update is now available for Red Hat Automation Platform 1.2.4. | 2021-10-08 | [https://access.redhat.com/errata/RHBA-2021:2955](https://access.redhat.com/errata/RHBA-2021:2955) |
| RHBA-2021:3472 | redhat | Red Hat Bug Fix Advisory: Red Hat Ansible Tower 3.8.4-1 - Container | Red Hat Ansible Tower 3.8.4-1 - Container | 2021-10-08 | [https://access.redhat.com/errata/RHBA-2021:3472](https://access.redhat.com/errata/RHBA-2021:3472) |
| RHSA-2021:2258 | redhat | Red Hat Security Advisory: rh-nginx118-nginx security update | An update for rh-nginx118-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-06-08 | [https://access.redhat.com/errata/RHSA-2021:2258](https://access.redhat.com/errata/RHSA-2021:2258) |
| RHSA-2021:2259 | redhat | Red Hat Security Advisory: nginx:1.18 security update | An update for the nginx:1.18 module is now available for Red Hat Enterprise Linux 8.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-06-08 | [https://access.redhat.com/errata/RHSA-2021:2259](https://access.redhat.com/errata/RHSA-2021:2259) |
| RHSA-2021:2278 | redhat | Red Hat Security Advisory: rh-nginx116-nginx security update | An update for rh-nginx116-nginx is now available for Red Hat Software Collections.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-06-09 | [https://access.redhat.com/errata/RHSA-2021:2278](https://access.redhat.com/errata/RHSA-2021:2278) |
| RHSA-2021:2290 | redhat | Red Hat Security Advisory: nginx:1.16 security update | An update for the nginx:1.16 module is now available for Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 8.1 Extended Update Support, and Red Hat Enterprise Linux 8.2 Extended Update Support.<br>Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. | 2021-06-09 | [https://access.redhat.com/errata/RHSA-2021:2290](https://access.redhat.com/errata/RHSA-2021:2290) |
| RHSA-2021:3653 | redhat | Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.1.11 security fix and container updates | Red Hat Advanced Cluster Management for Kubernetes 2.1.11 General Availability release images, which provide a security fix and update the container images.<br>Red Hat Product Security has rated this update as having a security impact  
of Low. A Common Vulnerability Scoring System (CVSS) base score, which  
gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2021-09-25 | [https://access.redhat.com/errata/RHSA-2021:3653](https://access.redhat.com/errata/RHSA-2021:3653) |
| RHSA-2021:3873 | redhat | Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.2.9 security, bug, and container updates | Red Hat Advanced Cluster Management for Kubernetes 2.2.9 General Availability release images, which provide security updates, one or more container updates, and bug fixes.<br>Red Hat Product Security has rated this update as having a security impact  
of Important. A Common Vulnerability Scoring System (CVSS) base score,  
which gives a detailed severity rating, is available for each vulnerability  
from the CVE link(s) in the References section. | 2021-10-16 | [https://access.redhat.com/errata/RHSA-2021:3873](https://access.redhat.com/errata/RHSA-2021:3873) |
| RHSA-2021:3925 | redhat | Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.3.3 bug fix, security, and image updates | Red Hat Advanced Cluster Management for Kubernetes 2.3.3 General Availability release images, which fix bugs, provide security fixes, and update container images.<br>Red Hat Product Security has rated this update as having a security impact  
of Important. A Common Vulnerability Scoring System (CVSS) base score,  
which gives a detailed severity rating, is available for each vulnerability  
from the CVE links in the References section. | 2021-10-21 | [https://access.redhat.com/errata/RHSA-2021:3925](https://access.redhat.com/errata/RHSA-2021:3925) |
| RHSA-2021:4618 | redhat | Red Hat Security Advisory: Red Hat Advanced Cluster Management 2.4 images and security updates | Red Hat Advanced Cluster Management for Kubernetes 2.4.0 General  
Availability release images, which fix several bugs and security issues.<br>Red Hat Product Security has rated this update as having a security impact  
of Important. A Common Vulnerability Scoring System (CVSS) base score,  
which gives a detailed severity rating, is available for each vulnerability from  
the CVE link(s) in the References section. | 2021-11-12 | [https://access.redhat.com/errata/RHSA-2021:4618](https://access.redhat.com/errata/RHSA-2021:4618) |
| FEDORA-2021-393d698493 | fedora | Fedora 34 Update: nginx-1.20.1-2.fc34 | Fix log permissions issue  ----  Security: 1-byte memory overwrite might occur  
during DNS server        response processing if the "resolver" directive was  
used, allowing an        attacker who is able to forge UDP packets from the DNS  
server to        cause worker process crash or, potentially, arbitrary code  
execution        (CVE-2021-23017). | 2021-06-12 | [https://bodhi.fedoraproject.org/updates/FEDORA-2021-393d698493](https://bodhi.fedoraproject.org/updates/FEDORA-2021-393d698493) |
| FEDORA-2021-b37cffac0d | fedora | Fedora 33 Update: nginx-1.20.1-2.fc33 | Fix log permissions issue  ----  Security: 1-byte memory overwrite might occur  
during DNS server        response processing if the "resolver" directive was  
used, allowing an        attacker who is able to forge UDP packets from the DNS  
server to        cause worker process crash or, potentially, arbitrary code  
execution        (CVE-2021-23017). | 2021-06-12 | [https://bodhi.fedoraproject.org/updates/FEDORA-2021-b37cffac0d](https://bodhi.fedoraproject.org/updates/FEDORA-2021-b37cffac0d) |
| openSUSE-SU-2021:1815-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2021-23017: nginx DNS resolver off-by-one heap write (bsc#1186126) | 2021-07-14 | [https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HKTQ3CIPQ5OLG2MFTQXWBRDD66NWPZBF/](https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/HKTQ3CIPQ5OLG2MFTQXWBRDD66NWPZBF/) |
| openSUSE-SU-2021:0835-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2021-23017: nginx DNS resolver off-by-one heap write (bsc#1186126)<br>This update was imported from the SUSE:SLE-15-SP1:Update update project. | 2021-06-05 | [https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MGLK2LDX6LXOTDRBNVVWP2BFD3ISKDXF/](https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MGLK2LDX6LXOTDRBNVVWP2BFD3ISKDXF/) |
| glsa202105-38 | gentoo | nginx: Remote code execution | <p>It was discovered that nginx did not properly handle DNS responses when  
      “resolver” directive is used.  
    </p> | 2021-05-28 | [https://security.gentoo.org/glsa/202105-38](https://security.gentoo.org/glsa/202105-38) |
| USN-4967-1 | canonical | nginx vulnerability | Luis Merino, Markus Vervier, and Eric Sesterhenn discovered that nginx  
incorrectly handled responses to the DNS resolver. A remote attacker could  
use this issue to cause nginx to crash, resulting in a denial of service,  
or possibly execute arbitrary code. | 2021-05-27 | [https://ubuntu.com/security/notices/USN-4967-1](https://ubuntu.com/security/notices/USN-4967-1) |
| USN-4967-2 | canonical | nginx vulnerability | USN-4967-1 fixed a vulnerability in nginx. This update provides  
the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.  
Original advisory details:  
Luis Merino, Markus Vervier, and Eric Sesterhenn discovered that nginx  
 incorrectly handled responses to the DNS resolver. A remote attacker could  
 use this issue to cause nginx to crash, resulting in a denial of service,  
 or possibly execute arbitrary code. | 2021-05-28 | [https://ubuntu.com/security/notices/USN-4967-2](https://ubuntu.com/security/notices/USN-4967-2) |
| CPUApr2022 | oracle | Oracle Critical Patch Update Advisory - April 2022 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2022-05-06 | [https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html) |
| CPUJan2022 | oracle | Oracle Critical Patch Update Advisory - January 2022 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2022-03-25 | [https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html) |
| CPUOct2021 | oracle | Oracle Critical Patch Update Advisory - October 2021 - Oracle CVRF | This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document. | 2021-11-06 | [https://www.oracle.com/security-alerts/cpuoct2021.html](https://www.oracle.com/security-alerts/cpuoct2021.html) |
| SUSE-SU-2021:1792-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2021-23017: nginx DNS resolver off-by-one heap write (bsc#1186126) | 2021-05-29 | [https://www.suse.com/support/update/announcement/2021/suse-su-20211792-1/](https://www.suse.com/support/update/announcement/2021/suse-su-20211792-1/) |
| SUSE-SU-2021:1814-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2021-23017: nginx DNS resolver off-by-one heap write (bsc#1186126) | 2021-06-02 | [https://www.suse.com/support/update/announcement/2021/suse-su-20211814-1/](https://www.suse.com/support/update/announcement/2021/suse-su-20211814-1/) |
| SUSE-SU-2021:1815-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2021-23017: nginx DNS resolver off-by-one heap write (bsc#1186126) | 2021-06-02 | [https://www.suse.com/support/update/announcement/2021/suse-su-20211815-1/](https://www.suse.com/support/update/announcement/2021/suse-su-20211815-1/) |
| SUSE-SU-2021:1839-1 | suse | Security update for nginx | This update for nginx fixes the following issues:<br>- CVE-2021-23017: nginx DNS resolver off-by-one heap write (bsc#1186126) | 2021-06-04 | [https://www.suse.com/support/update/announcement/2021/suse-su-20211839-1/](https://www.suse.com/support/update/announcement/2021/suse-su-20211839-1/) |