{"id":"UBUNTU-CVE-2021-40083","details":"Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof).","modified":"2025-07-16T07:43:13.770156Z","published":"2021-08-25T01:15:00Z","withdrawn":"2025-07-18T16:46:59Z","upstream":["CVE-2021-40083"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2021-40083"},{"type":"REPORT","url":"https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1169"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2021-40083"}],"affected":[{"package":{"name":"knot-resolver","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/knot-resolver@5.4.4-1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.4-1"}]}],"versions":["5.3.1-1","5.4.2-1","5.4.3-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"knot-resolver","binary_version":"5.4.4-1"},{"binary_name":"knot-resolver-dbgsym","binary_version":"5.4.4-1"},{"binary_name":"knot-resolver-doc","binary_version":"5.4.4-1"},{"binary_version":"5.4.4-1","binary_name":"knot-resolver-module-http"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-40083.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}