Corrective updates for stable branches of the DNS server , as well as the experimental branch 9.15.2 currently in development. The new releases address a vulnerability (CVE-2019-6471) caused by a race condition that could lead to a denial of service (process termination upon asserting) when blocking a large number of incoming packets.
Additionally, the new version 9.14.4 introduces support for the GeoIP2 API for connecting to an IP location database from the company
MaxMind (enabled through a build option of ‘--with-geoip2’). For GeoIP2, support for certain ACLs (such as checks based on network speed, organization, and country code) previously supported by the old GeoIP API has been discontinued by MaxMind. New metrics dnssec-sign and dnssec-refresh have also been added, which track the number of generated and updated DNSSEC signatures.
Additionally, it can be noted Knot DNS servers 2.8.3, which added a configuration file for the TLS certificate/key in kdig, improved logging for offline-KSK signatures and the RRL module, and expanded DNSSEC configuration checks.
An update for Knot Resolver 4.1.0 has also been released, which resolves (CVE-2019-10190, CVE-2019-10191): the possibility to bypass DNSSEC verification for requests with non-existent names (NXDOMAIN) and the ability to revert a DNSSEC-protected domain to an unprotected state through packet spoofing.
Source: opennet.ru
