Improper random number generation in github.com/coredns/coredns
Package
Affected versions
< 1.6.6
Patched versions
1.6.6
Description
Published to the GitHub Advisory Database
Mar 1, 2022
Reviewed
Mar 1, 2022
Last updated
Jan 11, 2023
Impact
CoreDNS before 1.6.6 (using go DNS package < 1.1.25) improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
Patches
The problem has been fixed in 1.6.6+.
References
For more information
Please consult our security guide for more information regarding our security process.
References