PT-2023-6785 · Isc+12 · Bind 9+12
Anat Bremler-Barr
+3
·
Published
2023-06-14
·
Updated
2024-10-03
·
CVE-2023-2828
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
BIND 9 versions 9.11.0 through 9.16.41
BIND 9 versions 9.18.0 through 9.18.15
BIND 9 versions 9.19.0 through 9.19.13
BIND 9 versions 9.11.3-S1 through 9.16.41-S1
BIND 9 versions 9.18.11-S1 through 9.18.15-S1
Description
The effectiveness of the cache-cleaning algorithm used in
named can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured max-cache-size limit to be significantly exceeded. This can lead to a denial of service, caused by a flaw that allows the named's configured cache size limit to be significantly exceeded, potentially exhausting all memory on the host.Recommendations
For BIND 9 versions 9.11.0 through 9.16.41, update to a version that includes a fix for this issue.
For BIND 9 versions 9.18.0 through 9.18.15, update to a version that includes a fix for this issue.
For BIND 9 versions 9.19.0 through 9.19.13, update to a version that includes a fix for this issue.
For BIND 9 versions 9.11.3-S1 through 9.16.41-S1, update to a version that includes a fix for this issue.
For BIND 9 versions 9.18.11-S1 through 9.18.15-S1, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to the
named instance to minimize the risk of exploitation.Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu