PT-2025-1630 · Isc+12 · Bind 9+12
Published
2025-01-29
·
Updated
2026-01-22
·
CVE-2024-11187
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
BIND 9 versions 9.11.0 through 9.11.37
BIND 9 versions 9.16.0 through 9.16.50
BIND 9 versions 9.18.0 through 9.18.32
BIND 9 versions 9.20.0 through 9.20.4
BIND 9 versions 9.21.0 through 9.21.3
BIND 9 versions 9.11.3-S1 through 9.11.37-S1
BIND 9 versions 9.16.8-S1 through 9.16.50-S1
BIND 9 versions 9.18.11-S1 through 9.18.32-S1
Description
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
Recommendations
BIND 9 versions 9.11.0 through 9.11.37 should update to a version outside of the affected range.
BIND 9 versions 9.16.0 through 9.16.50 should update to a version outside of the affected range.
BIND 9 versions 9.18.0 through 9.18.32 should update to a version outside of the affected range.
BIND 9 versions 9.20.0 through 9.20.4 should update to a version outside of the affected range.
BIND 9 versions 9.21.0 through 9.21.3 should update to a version outside of the affected range.
BIND 9 versions 9.11.3-S1 through 9.11.37-S1 should update to a version outside of the affected range.
BIND 9 versions 9.16.8-S1 through 9.16.50-S1 should update to a version outside of the affected range.
BIND 9 versions 9.18.11-S1 through 9.18.32-S1 should update to a version outside of the affected range.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu