CVE-2018-5735: Debian Linux

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only

Published 2019-10-30. Last modified 2026-06-17.