PT-2024-2753 · Isc+12 · Bind 9+12

Anat Bremler-Barr

+3

·

Published

2024-01-10

·

Updated

2024-10-21

·

CVE-2023-4408

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.0.0 through 9.16.45 BIND 9 versions 9.18.0 through 9.18.21 BIND 9 versions 9.19.0 through 9.19.19 BIND 9 versions 9.9.3-S1 through 9.11.37-S1 BIND 9 versions 9.16.8-S1 through 9.16.45-S1 BIND 9 versions 9.18.11-S1 through 9.18.21-S1
Description The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. A remote attacker could exploit this vulnerability to trigger an assertion failure by querying RFC 1918 reverse zones.
Recommendations For BIND 9 versions 9.0.0 through 9.16.45, update to a version outside of this range to mitigate the risk. For BIND 9 versions 9.18.0 through 9.18.21, update to a version outside of this range to mitigate the risk. For BIND 9 versions 9.19.0 through 9.19.19, update to a version outside of this range to mitigate the risk. For BIND 9 versions 9.9.3-S1 through 9.11.37-S1, update to a version outside of this range to mitigate the risk. For BIND 9 versions 9.16.8-S1 through 9.16.45-S1, update to a version outside of this range to mitigate the risk. For BIND 9 versions 9.18.11-S1 through 9.18.21-S1, update to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting access to the named instance to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2024:1781
ALSA-2024:1782
ALSA-2024:1789
ALSA-2024:2551
ALSA-2024:3271
ALT-PU-2024-9772
ALT-PU-2024-9774
AZL-34353
AZL-34560
BDU:2024-02883
CESA-2024_1781
CESA-2024_1782
CESA-2024_3271
CVE-2023-4408
DSA-5621-1
INFSA-2024_2551
INFSA-2024_3271
MGASA-2024-0038
OESA-2024-1323
OESA-2024-1324
OESA-2024-1325
OESA-2024-1326
OPENSUSE-SU-2024:13687-1
OPENSUSE-SU-2024_0574-1
OPENSUSE-SU-2024_0590-1
OPENSUSE-SU-2024_1982-1
RHSA-2024:1647
RHSA-2024:1648
RHSA-2024:1781
RHSA-2024:1782
RHSA-2024:1789
RHSA-2024:1800
RHSA-2024:1803
RHSA-2024:2551
RHSA-2024:2720
RHSA-2024:2721
RHSA-2024:2821
RHSA-2024:2890
RHSA-2024:3271
RHSA-2024:3741
RHSA-2024_1781
RHSA-2024_1782
RHSA-2024_1789
RHSA-2024_2551
RHSA-2024_3271
RHSA-2024_3741
RHSA-2025:0039
RLSA-2024:1781
RLSA-2024:1782
RLSA-2024:2551
RLSA-2024:3271
ROSA-SA-2024-2489
SUSE-SU-2024:0574-1
SUSE-SU-2024:0590-1
SUSE-SU-2024:1894-1
SUSE-SU-2024:1982-1
SUSE-SU-2024:2033-1
USN-6633-1
USN-6642-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu