Common Implementation Anti-Patterns Related to Domain Name System Resource Record Processing
RFC 9267, “Common Implementation Anti-Patterns Related to Domain Name System Resource Record Processing”, is an Informational document published in July 2022 by S. Dashevskyi, D. dos Santos, J. Wetzels, A. Amri. The canonical text is published by the RFC Editor.
Abstract
This memo describes common vulnerabilities related to Domain Name System (DNS) resource record (RR) processing as seen in several DNS client implementations. These vulnerabilities may lead to successful Denial-of-Service and Remote Code Execution attacks against the affected software. Where applicable, violations of RFC 1035 are mentioned.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 9267 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9266 Channel Bindings for TLS 1.3
- RFC 9268 IPv6 Minimum Path MTU Hop-by-Hop Option
- RFC 9265 Forward Erasure Correction Coding and Congestion Control in Transport
- RFC 9269 Experimental Scenarios of Information-Centric Networking Integration in 4G Mobile Networks
- RFC 9264 Linkset: Media Types and a Link Relation Type for Link Sets
- RFC 9270 GMPLS Signaling Extensions for Shared Mesh Protection
- RFC 9263 Network Service Header Metadata Type 2 Variable-Length Context Headers
- RFC 9271 Uninterruptible Power Supply Management Protocol -- Commands and Responses