CVE-2017-9105
Linux Debian vulnerability analysis and mitigation

Overview

A vulnerability was discovered in adns before version 1.5.2, identified as CVE-2017-9105. The issue involves pointer corruption that occurs when a nameserver speaks first due to an incorrect number of pointer dereferences. This vulnerability was discovered in 2017 and potentially allows for remote code execution (NVD, MITRE).

Technical details

The vulnerability stems from a pointer corruption issue in the DNS resolver library when processing responses from nameservers. The bug occurs specifically when a nameserver responds first and involves incorrect handling of pointer dereferences. The issue was discovered using AFL 2.35b fuzzing tool, as confirmed in the security advisory (ADNS Announce).

Impact

The vulnerability affects all adns callers and is exploitable through the local recursive resolver. The worst-case scenario is remote code execution, making this a critical security issue. The vulnerability impacts applications that use the adns library for DNS resolution (ADNS Announce, Fedora Update).

Exploitability

The vulnerability is exploitable through the local recursive resolver, potentially leading to remote code execution. The issue was serious enough to warrant immediate patching and was one of several critical vulnerabilities addressed in version 1.5.2 (ADNS Announce).

Mitigation and workarounds

The vulnerability was fixed in adns version 1.5.2. Users are strongly advised to upgrade to this version or later. The fix was also included in version 1.6.0, which contains additional build fixes and tests. Package maintainers have provided updates through their respective repositories, such as Fedora's update to version 1.6.0 (Fedora Update).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-94106HIGH8.7
  • Linux Debian logoLinux Debian
  • php-getid3
NoNoSep 20, 2026
CVE-2026-93990HIGH8.7
  • Linux Debian logoLinux Debian
  • expat
NoYesSep 19, 2026
CVE-2026-94108HIGH8.3
  • Linux Debian logoLinux Debian
  • php-getid3
NoNoSep 20, 2026
CVE-2026-93962MEDIUM5.5
  • Linux Debian logoLinux Debian
  • kamailio
NoNoSep 20, 2026
CVE-2026-82560NONEN/A
  • Linux Debian logoLinux Debian
  • seal-perl
NoYesSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management