A denial of service flaw was found in the way BIND handled a query response containing CNAME or DNAME resource records in an unusual order. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS response. unexpectedly with an assertion failure via a specially crafted command. https://nvd.nist.gov/vuln/detail/CVE-2017-3137