Server Name Indication and Hostname Validation Issues in systemd by systemd
CVE-2018-21029
9.8CRITICAL
What is CVE-2018-21029?
systemd versions 239 through 245 exhibit a weakness in their handling of DNS Over TLS, permitting any certificate signed by a trusted certificate authority without proper hostname validation due to the absence of Server Name Indication (SNI). This may lead to potential security risks where attackers could exploit the lack of hostname verification during DNS queries, raising concerns over the integrity of encrypted communications.
