PT-2024-3868 · Isc+10 · Bind 9+10

Published

2024-01-10

·

Updated

2025-03-29

·

CVE-2023-5679

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.16.12 through 9.16.45 BIND 9 versions 9.18.0 through 9.18.21 BIND 9 versions 9.19.0 through 9.19.19 BIND 9 versions 9.16.12-S1 through 9.16.45-S1 BIND 9 versions 9.18.11-S1 through 9.18.21-S1
Description A bad interaction between DNS64 and serve-stale may cause named to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue can be exploited by a remote attacker to trigger an assertion failure, potentially leading to a denial of service.
Recommendations For versions 9.16.12 through 9.16.45, consider disabling the DNS64 and serve-stale features until a patch is available. For versions 9.18.0 through 9.18.21, consider disabling the DNS64 and serve-stale features until a patch is available. For versions 9.19.0 through 9.19.19, consider disabling the DNS64 and serve-stale features until a patch is available. For versions 9.16.12-S1 through 9.16.45-S1, consider disabling the DNS64 and serve-stale features until a patch is available. For versions 9.18.11-S1 through 9.18.21-S1, consider disabling the DNS64 and serve-stale features until a patch is available. As a temporary workaround, consider restricting access to the named parameter to minimize the risk of exploitation.

Exploit

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:1781
ALSA-2024:1789
ALSA-2024:2551
AZL-34351
AZL-34564
BDU:2024-02902
BDU:2024-04269
CESA-2024_1781
CVE-2023-5679
DSA-5621-1
INFSA-2024_2551
MGASA-2024-0038
OESA-2024-1323
OESA-2024-1324
OESA-2024-1325
OESA-2024-1326
OPENSUSE-SU-2024:13687-1
OPENSUSE-SU-2024_0574-1
OPENSUSE-SU-2024_0590-1
RHSA-2024:1647
RHSA-2024:1648
RHSA-2024:1781
RHSA-2024:1789
RHSA-2024:1800
RHSA-2024:1803
RHSA-2024:2551
RHSA-2024_1781
RHSA-2024_1789
RHSA-2024_2551
RLSA-2024:1781
RLSA-2024:2551
SUSE-SU-2024:0574-1
SUSE-SU-2024:0590-1
USN-6633-1

Affected Products

Almalinux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu