PT-2023-6785 · Isc+12 · Bind 9+12

Anat Bremler-Barr

+3

·

Published

2023-06-14

·

Updated

2024-10-03

·

CVE-2023-2828

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.11.0 through 9.16.41 BIND 9 versions 9.18.0 through 9.18.15 BIND 9 versions 9.19.0 through 9.19.13 BIND 9 versions 9.11.3-S1 through 9.16.41-S1 BIND 9 versions 9.18.11-S1 through 9.18.15-S1
Description The effectiveness of the cache-cleaning algorithm used in named can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured max-cache-size limit to be significantly exceeded. This can lead to a denial of service, caused by a flaw that allows the named's configured cache size limit to be significantly exceeded, potentially exhausting all memory on the host.
Recommendations For BIND 9 versions 9.11.0 through 9.16.41, update to a version that includes a fix for this issue. For BIND 9 versions 9.18.0 through 9.18.15, update to a version that includes a fix for this issue. For BIND 9 versions 9.19.0 through 9.19.13, update to a version that includes a fix for this issue. For BIND 9 versions 9.11.3-S1 through 9.16.41-S1, update to a version that includes a fix for this issue. For BIND 9 versions 9.18.11-S1 through 9.18.15-S1, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to the named instance to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:4099
ALSA-2023:4100
ALSA-2023:4102
ALT-PU-2023-2044
ALT-PU-2023-2102
ALT-PU-2024-1988
ALT-PU-2024-9772
ALT-PU-2024-9774
AZL-27203
AZL-27238
BDU:2023-07642
CESA-2023_4100
CESA-2023_4102
CESA-2023_4152
CVE-2023-2828
DLA-3498-1
DSA-5439-1
OESA-2023-1384
OESA-2023-1505
OPENSUSE-SU-2023_2954-1
OPENSUSE-SU-2024:13015-1
RHSA-2023:4005
RHSA-2023:4037
RHSA-2023:4099
RHSA-2023:4100
RHSA-2023:4101
RHSA-2023:4102
RHSA-2023:4152
RHSA-2023:4153
RHSA-2023:4154
RHSA-2023:4332
RHSA-2023_4099
RHSA-2023_4100
RHSA-2023_4102
RHSA-2023_4152
RLSA-2023:4099
RLSA-2023:4100
RLSA-2023:4102
ROSA-SA-2023-2279
ROSA-SA-2024-2489
SUSE-SU-2023:2667-1
SUSE-SU-2023:2789-1
SUSE-SU-2023:2793-1
SUSE-SU-2023:2794-1
SUSE-SU-2023:2836-1
SUSE-SU-2023:2954-1
SUSE-SU-2023_2667-1
SUSE-SU-2023_2789-1
SUSE-SU-2023_2793-1
SUSE-SU-2023_2794-1
SUSE-SU-2023_2836-1
SUSE-SU-2023_2954-1
USN-6183-1
USN-6183-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu