PT-2024-5336 · Isc+12 · Bind 9+12

Published

2024-07-10

·

Updated

2025-02-03

·

CVE-2024-1737

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.11.0 through 9.11.37 BIND 9 versions 9.16.0 through 9.16.50 BIND 9 versions 9.18.0 through 9.18.27 BIND 9 versions 9.19.0 through 9.19.24 BIND 9 versions 9.11.4-S1 through 9.11.37-S1 BIND 9 versions 9.16.8-S1 through 9.16.50-S1 BIND 9 versions 9.18.11-S1 through 9.18.27-S1
Description Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. The issue is related to an error when a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache. By sending a stream of SIG(0) signed requests, a remote attacker could exploit this vulnerability to exhaust all available CPU resources.
Recommendations For BIND 9 versions 9.11.0 through 9.11.37, update to a version outside of this range to mitigate the issue. For BIND 9 versions 9.16.0 through 9.16.50, update to a version outside of this range to mitigate the issue. For BIND 9 versions 9.18.0 through 9.18.27, update to a version outside of this range to mitigate the issue. For BIND 9 versions 9.19.0 through 9.19.24, update to a version outside of this range to mitigate the issue. For BIND 9 versions 9.11.4-S1 through 9.11.37-S1, update to a version outside of this range to mitigate the issue. For BIND 9 versions 9.16.8-S1 through 9.16.50-S1, update to a version outside of this range to mitigate the issue. For BIND 9 versions 9.18.11-S1 through 9.18.27-S1, update to a version outside of this range to mitigate the issue. As a temporary workaround, consider restricting the use of "KEY" Resource Records in zones to minimize the risk of exploitation.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2024:5231
ALSA-2024:5390
ALSA-2024:5524
ALT-PU-2024-12002
ALT-PU-2024-12367
ALT-PU-2024-12474
ALT-PU-2024-13685
ALT-PU-2025-2228
AZL-46981
AZL-46988
AZL-47030
BDU:2024-05964
CESA-2024_5390
CESA-2024_5524
CVE-2024-1737
DSA-5734-1
DSA-5734-2
INFSA-2024_5231
INFSA-2024_5390
INFSA-2024_5524
MGASA-2024-0342
OESA-2024-1969
OESA-2024-1970
OESA-2024-1971
OESA-2024-1972
OESA-2024-1973
OESA-2024-2390
OPENSUSE-SU-2024:14217-1
RHSA-2024:5231
RHSA-2024:5390
RHSA-2024:5418
RHSA-2024:5524
RHSA-2024:5525
RHSA-2024:5655
RHSA-2024:5813
RHSA-2024:5838
RHSA-2024:5871
RHSA-2024:5894
RHSA-2024:5907
RHSA-2024:5908
RHSA-2024:5930
RHSA-2024_5231
RHSA-2024_5390
RHSA-2024_5524
RLSA-2024:5231
ROSA-SA-2024-2514
SUSE-SU-2024:2636-1
SUSE-SU-2024:2810-1
SUSE-SU-2024:2811-1
SUSE-SU-2024:2862-1
SUSE-SU-2024:2863-1
SUSE-SU-2024:2868-1
SUSE-SU-2024_2810-1
SUSE-SU-2024_2811-1
SUSE-SU-2024_2862-1
SUSE-SU-2024_2863-1
SUSE-SU-2024_2868-1
USN-6909-1
USN-6909-2
USN-6909-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu