Описание
A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
A flaw was found in BIND, a widely used Domain Name System (DNS) software. A remote attacker could exploit this vulnerability by sending a large number of specially crafted, invalid DNSSEC (Domain Name System Security Extensions) records to a BIND recursive resolver. This could lead to excessive resource consumption, resulting in a Denial of Service (DoS) for the affected resolver.
Отчет
This Moderate impact flaw in BIND recursive resolvers can lead to a denial of service due to excessive resource consumption when processing specific invalid DNSSEC records. Red Hat's default BIND configurations include max-records-per-type and max-types-per-name limits, which help reduce the exposure and prevent a more severe impact.
Меры по смягчению последствий
To mitigate potential denial of service, ensure that the BIND recursive resolver's configuration includes appropriate limits for max-records-per-type and max-types-per-name within the named.conf file. These settings help control resource consumption when encountering invalid DNSSEC records. A restart of the named service is required for any configuration changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 6 | bind | Not affected | ||
| Red Hat Enterprise Linux 7 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 8 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 8 | bind9.16 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | bind | Fix deferred | ||
| Red Hat Enterprise Linux 9 | bind9.18 | Fix deferred | ||
| Red Hat Enterprise Linux 9 | dhcp | Not affected | ||
| Red Hat Hardened Images | bind | Affected | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
(A BIND recursive resolver may experience excessive resource consumptio ...)
A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
A BIND recursive resolver may experience excessive resource consumptio ...
A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
5.3 Medium
CVSS3