PT-2024-5485 · Isc+12 · Bind 9+12

Published

2024-04-23

·

Updated

2024-11-18

·

CVE-2024-4076

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.11.33-S1 through 9.11.37-S1 BIND 9 versions 9.16.13 through 9.16.50 BIND 9 versions 9.16.13-S1 through 9.16.50-S1 BIND 9 versions 9.18.0 through 9.18.27 BIND 9 versions 9.18.11-S1 through 9.18.27-S1 BIND 9 versions 9.19.0 through 9.19.24
Description Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. The issue is related to the use of the assert() function or similar operators. Exploitation of the issue may allow a remote attacker to cause a denial of service by sending specially crafted requests.
Recommendations For BIND 9 versions 9.11.33-S1 through 9.11.37-S1, update to a version that contains a fix for this issue. For BIND 9 versions 9.16.13 through 9.16.50, update to a version that contains a fix for this issue. For BIND 9 versions 9.16.13-S1 through 9.16.50-S1, update to a version that contains a fix for this issue. For BIND 9 versions 9.18.0 through 9.18.27, update to a version that contains a fix for this issue. For BIND 9 versions 9.18.11-S1 through 9.18.27-S1, update to a version that contains a fix for this issue. For BIND 9 versions 9.19.0 through 9.19.24, update to a version that contains a fix for this issue. As a temporary workaround, consider disabling the assert() function or similar operators until a patch is available. Restrict access to the local authoritative zone data to minimize the risk of exploitation. Avoid using the KEY Resource Record in the DNSSEC-signed domain in cache until the issue is resolved.

Fix

DoS

Assertion Failure

Weakness Enumeration

Related Identifiers

ALSA-2024:5231
ALSA-2024:5390
ALT-PU-2024-12002
ALT-PU-2024-12474
ALT-PU-2024-13685
AZL-46966
AZL-46984
BDU:2024-06134
CESA-2024_5390
CVE-2024-4076
DSA-5734-1
DSA-5734-2
INFSA-2024_5231
INFSA-2024_5390
MGASA-2024-0342
OESA-2024-1969
OESA-2024-1970
OESA-2024-1971
OESA-2024-1973
OPENSUSE-SU-2024:14217-1
RHSA-2024:5231
RHSA-2024:5390
RHSA-2024:5418
RHSA-2024:5525
RHSA-2024:5813
RHSA-2024:5907
RHSA-2024_5231
RHSA-2024_5390
RLSA-2024:5231
SUSE-SU-2024:2636-1
SUSE-SU-2024:2862-1
SUSE-SU-2024:2863-1
USN-6909-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu