diff --git a/doc/arm/notes-9.11.30.xml b/doc/arm/notes-9.11.30.xml index d3b11606ab..39c483791a 100644 --- a/doc/arm/notes-9.11.30.xml +++ b/doc/arm/notes-9.11.30.xml @@ -37,6 +37,23 @@ bringing this vulnerability to our attention. [GL #2540] + + + When a server's configuration set the + tkey-gssapi-keytab or + tkey-gssapi-credential option, a specially crafted + GSS-TSIG query could cause a buffer overflow in the ISC implementation + of SPNEGO (a protocol enabling negotiation of the security mechanism + used for GSSAPI authentication). This flaw could be exploited to crash + named binaries compiled for 64-bit platforms, and + could enable remote code execution when named was + compiled for 32-bit platforms. (CVE-2021-25216) + + + This vulnerability was reported to us as ZDI-CAN-13347 by Trend Micro + Zero Day Initiative. [GL #2604] + +