RFC 9267: Common Implementation Anti-Patterns Related to Domain Name System (DNS) Resource Record (RR) Processing
In plain English — editorial summary, not part of the RFC
This memo describes common vulnerabilities related to Domain Name System (DNS) resource record (RR) processing as seen in several DNS client implementations. These vulnerabilities may lead to successful Denial-of-Service and Remote Code Execution attacks against the affected software. Where applicable, violations of RFC 1035 are mentioned.
Document record
- Document ID
- RFC9267
- Published
- July 2022
- Authors
- S. Dashevskyi; D. dos Santos; J. Wetzels; A. Amri
- Status
- INFORMATIONAL
- Stream
- INDEPENDENT
- Area
- —
- Pages
- 16
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9414Unfortunate History of Transient Numeric IdentifiersCurrent
July 2023
- RFC 9415On the Generation of Transient Numeric IdentifiersCurrent
July 2023
- RFC 9416Security Considerations for Transient Numeric Identifiers Employed in Network ProtocolsCurrent
July 2023
- RFC 7739Security Implications of Predictable Fragment Identification ValuesCurrent
February 2016
- RFC 7203An Incident Object Description Exchange Format (IODEF) Extension for Structured Cybersecurity InformationCurrent
April 2014
- RFC 6980Security Implications of IPv6 Fragmentation with IPv6 Neighbor DiscoveryCurrent
August 2013
- RFC 6946Processing of IPv6 "Atomic" FragmentsCurrent
May 2013
- RFC 6274Security Assessment of the Internet Protocol Version 4Current
July 2011
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?