Описание
On a resolver configured to use dns64, if an applicable answer from the authoritative server is malformed in a specific way, the resolver named process will exit unexpectedly.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
A flaw was found in BIND. When a resolver is configured to use DNS64, a specially crafted, malformed answer from an authoritative server can cause the named process to exit unexpectedly. This can lead to a Denial of Service (DoS) for clients relying on the affected resolver.
Отчет
Important: This denial of service vulnerability affects BIND resolvers configured to use the dns64 feature. A specially crafted malformed DNS64 response from an authoritative server can cause the named process to unexpectedly terminate, leading to service unavailability. Exploitation requires the dns64 feature to be explicitly enabled in the resolver's configuration.
Меры по смягчению последствий
To mitigate this issue, disable the dns64 feature in the BIND resolver configuration if it is not required. This can be done by removing or commenting out the dns64 configuration block in named.conf or related configuration files. After modifying the configuration, the BIND service (named) must be reloaded or restarted for the changes to take effect. This action may temporarily interrupt DNS resolution services.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bind | Affected | ||
| Red Hat Enterprise Linux 6 | bind | Not affected | ||
| Red Hat Enterprise Linux 7 | bind | Affected | ||
| Red Hat Enterprise Linux 8 | bind | Affected | ||
| Red Hat Enterprise Linux 8 | bind9.16 | Affected | ||
| Red Hat Enterprise Linux 9 | bind | Affected | ||
| Red Hat Enterprise Linux 9 | bind9.18 | Affected | ||
| Red Hat Enterprise Linux 9 | dhcp | Not affected | ||
| Red Hat Hardened Images | bind | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
(On a resolver configured to use ``dns64``, if an applicable answer fro ...)
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
On a resolver configured to use ``dns64``, if an applicable answer fro ...
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
7.5 High
CVSS3