PT-2024-14985 · Isc+9 · Bind 9+9

Published

2024-02-13

·

Updated

2024-10-22

·

CVE-2023-6516

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.16.0 through 9.16.45 BIND 9 versions 9.16.8-S1 through 9.16.45-S1
Description The issue affects the named process running as a recursive resolver, which attempts to clean up its cache database using several methods, including asynchronous ones. If the resolver is continuously processing query patterns that trigger this type of cache-database maintenance, it may not be able to handle the cleanup events in a timely manner. This enables the list of queued cleanup events to grow infinitely large over time, allowing the configured max-cache-size limit to be significantly exceeded. A remote attacker could exploit this vulnerability to trigger an assertion failure by querying RFC 1918 reverse zones.
Recommendations For BIND 9 versions 9.16.0 through 9.16.45, update to a version that includes the fix for this issue. For BIND 9 versions 9.16.8-S1 through 9.16.45-S1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the max-cache-size limit to prevent excessive growth of queued cleanup events. Restrict access to the recursive resolver to minimize the risk of exploitation.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2024:1781
ALSA-2024:1789
ALSA-2024:2551
AZL-34561
CESA-2024_1781
CVE-2023-6516
DSA-5621-1
INFSA-2024_2551
OESA-2024-1323
OESA-2024-1324
OESA-2024-1325
OESA-2024-1326
OPENSUSE-SU-2024:13687-1
OPENSUSE-SU-2024_0574-1
OPENSUSE-SU-2024_0590-1
OPENSUSE-SU-2024_1982-1
RHSA-2024:1647
RHSA-2024:1648
RHSA-2024:1781
RHSA-2024:1789
RHSA-2024:1800
RHSA-2024:1803
RHSA-2024:2551
RHSA-2024_1781
RHSA-2024_1789
RHSA-2024_2551
RLSA-2024:1781
RLSA-2024:2551
SUSE-SU-2024:0574-1
SUSE-SU-2024:0590-1
SUSE-SU-2024:1982-1
SUSE-SU-2024:2033-1
USN-6642-1

Affected Products

Almalinux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu