The vendor explicitly identifies these products as affected by this CVE.
- python-zeroconf.src as a component of Red Hat OpenShift Container Platform 4
- python3-zeroconf as a component of Red Hat OpenShift Container Platform 4
- python3-zeroconf as a component of Red Hat OpenStack Platform 16.2
- python3-zeroconf as a component of Red Hat OpenStack Platform 17.1
- python-zeroconf.src as a component of Red Hat OpenStack Platform 18.0
- Summary
- A flaw was found in Zeroconf, a Python library for multicast DNS service discovery. An unauthenticated attacker on the local network can exploit a vulnerability in how the system processes incoming DNS records. By sending a specially crafted record with an excessive length, the attacker can cause the system's DNS cache and service information to be populated with manipulated or truncated data. This could lead to incorrect service discovery or other data integrity issues within the affected system.
- Remediation
- Upgrade to zeroconf 0.149.16 or later once packaged in the affected Red Hat product. Where upgrading isn't immediately possible, restricting the affected host's exposure to the local network segment (network segmentation or firewalling multicast DNS traffic on UDP/5353) reduces the practical attack surface, since exploitation requires local-link access.
