PT-2025-1630 · Isc+12 · Bind 9+12

Published

2025-01-29

·

Updated

2026-01-22

·

CVE-2024-11187

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.11.0 through 9.11.37 BIND 9 versions 9.16.0 through 9.16.50 BIND 9 versions 9.18.0 through 9.18.32 BIND 9 versions 9.20.0 through 9.20.4 BIND 9 versions 9.21.0 through 9.21.3 BIND 9 versions 9.11.3-S1 through 9.11.37-S1 BIND 9 versions 9.16.8-S1 through 9.16.50-S1 BIND 9 versions 9.18.11-S1 through 9.18.32-S1
Description It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
Recommendations BIND 9 versions 9.11.0 through 9.11.37 should update to a version outside of the affected range. BIND 9 versions 9.16.0 through 9.16.50 should update to a version outside of the affected range. BIND 9 versions 9.18.0 through 9.18.32 should update to a version outside of the affected range. BIND 9 versions 9.20.0 through 9.20.4 should update to a version outside of the affected range. BIND 9 versions 9.21.0 through 9.21.3 should update to a version outside of the affected range. BIND 9 versions 9.11.3-S1 through 9.11.37-S1 should update to a version outside of the affected range. BIND 9 versions 9.16.8-S1 through 9.16.50-S1 should update to a version outside of the affected range. BIND 9 versions 9.18.11-S1 through 9.18.32-S1 should update to a version outside of the affected range.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:1670
ALSA-2025:1675
ALSA-2025:1676
ALSA-2025:1681
ALT-PU-2025-2222
ALT-PU-2025-2226
ALT-PU-2025-2228
ALT-PU-2025-2272
ALT-PU-2025-2330
AZL-56093
AZL-56097
AZL-56198
BDU:2025-01459
CESA-2025_1675
CESA-2025_1676
CVE-2024-11187
DLA-4050-1
DSA-5854-1
INFSA-2025_1670
INFSA-2025_1675
INFSA-2025_1676
INFSA-2025_1681
MGASA-2025-0036
OESA-2025-1105
OESA-2025-1106
OESA-2025-1172
OESA-2025-1215
OESA-2025-1341
OESA-2025-1558
OPENSUSE-SU-2025:14719-1
OPENSUSE-SU-2025_0355-1
OPENSUSE-SU-2025_0359-1
OPENSUSE-SU-2025_0384-1
OPENSUSE-SU-2025_0427-1
RHSA-2025:1664
RHSA-2025:1665
RHSA-2025:1666
RHSA-2025:1669
RHSA-2025:1670
RHSA-2025:1674
RHSA-2025:1675
RHSA-2025:1676
RHSA-2025:1678
RHSA-2025:1679
RHSA-2025:1681
RHSA-2025:1684
RHSA-2025:1685
RHSA-2025:1687
RHSA-2025:1691
RHSA-2025:1718
RHSA-2025_1670
RHSA-2025_1675
RHSA-2025_1676
RHSA-2025_1681
RLSA-2025:1670
RLSA-2025:1675
RLSA-2025:1676
RLSA-2025:1681
ROSA-SA-2025-2866
SUSE-SU-2025:01787-1
SUSE-SU-2025:0337-1
SUSE-SU-2025:0355-1
SUSE-SU-2025:0359-1
SUSE-SU-2025:0384-1
SUSE-SU-2025:0389-1
SUSE-SU-2025:0427-1
SUSE-SU-2025_01787-1
SUSE-SU-2025_0355-1
SUSE-SU-2025_0359-1
SUSE-SU-2025_0384-1
SUSE-SU-2025_0389-1
SUSE-SU-2025_0427-1
USN-7241-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu