CVE-2021-23017 is an off-by-one vulnerability in nginx's DNS resolver function ngx_resolver_copy(). It is triggered when DNS labels are followed by a pointer to a root domain name. An attacker able to forge UDP packets appearing to originate from the DNS server can cause a one-byte memory overwrite in an nginx worker process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains three Python proof-of-concept (PoC) scripts (poc.py, poc2.py, poc3.py) targeting CVE-2021-23017, a critical vulnerability in NGINX's DNS resolver (versions 0.6.18–1.20.0). The exploit aims to cause a Denial of Service (DoS) by sending specially crafted DNS responses with an excessively long domain name, triggering a buffer overflow and crashing the NGINX server. - The scripts use the scapy library to sniff for DNS queries from the target and respond with malicious DNS packets. They also use curl and dig to trigger DNS queries from the target to the attacker's DNS server. - poc.py is a basic PoC that listens for DNS queries and sends malicious responses. - poc2.py adds direct DNS packet sending, subnet checking, and triggers DNS queries using both curl and dig. It also sets the system resolver to the attacker's DNS server. - poc3.py is the most advanced, running all attack components in parallel (sniffing, sending malicious DNS, and triggering queries) for maximum efficiency and firewall evasion. The repository includes a README with detailed setup and usage instructions, including configuring dnsmasq and verifying the attack's success. The exploit is operational and can reliably crash vulnerable NGINX servers if the attacker can control or spoof DNS responses to the target. The main fingerprintable endpoint is the long domain name used in the attack, and the exploit requires network access to the target's DNS traffic.
This repository contains a single Python script that demonstrates a proof-of-concept exploit for CVE-2021-23017, a heap corruption vulnerability in Nginx 1.14's DNS resolver. The script acts as a UDP server on port 1053, waiting for incoming DNS requests. Upon receiving a request, it parses the DNS query and crafts a malicious CNAME response with a specially constructed payload (a long string of 'A's) designed to trigger the vulnerability in the target Nginx server. The script is self-contained, does not require external dependencies, and is intended for local testing or demonstration of the vulnerability. No hardcoded external endpoints are present, but the script itself listens on all interfaces (0.0.0.0) and port 1053. The exploit is a POC and does not provide a shell or advanced post-exploitation capabilities.
This repository is a proof-of-concept (POC) exploit for CVE-2021-23017, a vulnerability in nginx's DNS resolver. The exploit targets nginx instances configured with the 'resolver' directive and relies on the attacker's ability to spoof UDP packets from the DNS server. The main script, 'poc.py', uses Python and the Scapy library to perform ARP poisoning between the target and its DNS server, intercept DNS requests, and send a specially crafted DNS response designed to trigger a 1-byte memory overwrite in nginx. The exploit requires network access to the target and the ability to manipulate ARP and DNS traffic. The repository includes a README describing the vulnerability, the exploit script, and a requirements file specifying the Scapy dependency. No hardcoded IP addresses or domains are present; the script takes the target and DNS server IPs as arguments. The exploit demonstrates the vulnerability's impact (potential crash or other effects) but does not provide a weaponized or post-exploitation payload.
This repository is a proof-of-concept (PoC) exploit for CVE-2021-23017, a DNS parsing vulnerability in NGINX. The main file, 'poc.py', is a Python script that uses Scapy to perform ARP poisoning between a target and its DNS server, allowing the attacker to intercept and modify DNS traffic. Once the ARP poisoning is successful, the script listens for DNS requests from the target and injects a specially crafted DNS response designed to trigger the vulnerability. The exploit requires the attacker to have network access to both the target and its DNS server. The repository also includes a README with usage instructions and a requirements.txt specifying the Scapy dependency. No hardcoded IP addresses are present in the code; the user must supply them as arguments. The exploit demonstrates the vulnerability but does not provide a weaponized or fully automated attack chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An off-by-one vulnerability in nginx's ngx_resolver_copy() DNS resolver function. The Rocky Linux 8 host has an affected nginx package according to CIQ advisory crlsa-2021_2290.
An off-by-one flaw in nginx's DNS resolver function ngx_resolver_copy(), affecting certain crafted DNS responses involving labels followed by a pointer to the root domain name. The notice identifies affected nginx packages on Rocky Linux 8.
A specific vulnerability mentioned as an example of an issue OpenVAS can detect even when it is not obvious from service banners.
An nginx DNS resolver vulnerability listed by Shodan InternetDB for the host.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.