CVE-2017-9108: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.

An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() would have done. Without this fix, adnshost may read and process one byte beyond the buffer, perhaps crashing or perhaps somehow leaking the value of that byte.

Affected products

  • Fedoraproject Fedora: version 31 only; version 32 only
  • GNU Adns: before 1.5.2 (fixed in 1.5.2)
  • Opensuse Leap: version 15.1 only

Published 2020-06-18. Last modified 2026-06-17.