Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2024:2862-1

Опубликовано: 09 авг. 2024
Источник: suse-cvrf

Описание

Security update for bind

This update for bind fixes the following issues:

Update to 9.16.50:

  • Bug Fixes:
    • A regression in cache-cleaning code enabled memory use to grow significantly more quickly than before, until the configured max-cache-size limit was reached. This has been fixed.
    • Using rndc flush inadvertently caused cache cleaning to become less effective. This could ultimately lead to the configured max-cache-size limit being exceeded and has now been fixed.
    • The logic for cleaning up expired cached DNS records was tweaked to be more aggressive. This change helps with enforcing max-cache-ttl and max-ncache-ttl in a timely manner.
    • It was possible to trigger a use-after-free assertion when the overmem cache cleaning was initiated. This has been fixed. New Features:
    • Added RESOLVER.ARPA to the built in empty zones.
  • Security Fixes:
    • It is possible to craft excessively large numbers of resource record types for a given owner name, which has the effect of slowing down database processing. This has been addressed by adding a configurable limit to the number of records that can be stored per name and type in a cache or zone database. The default is 100, which can be tuned with the new max-types-per-name option. (CVE-2024-1737, bsc#1228256)
    • Validating DNS messages signed using the SIG(0) protocol (RFC 2931) could cause excessive CPU load, leading to a denial-of-service condition. Support for SIG(0) message validation was removed from this version of named. (CVE-2024-1975, bsc#1228257)
    • When looking up the NS records of parent zones as part of looking up DS records, it was possible for named to trigger an assertion failure if serve-stale was enabled. This has been fixed. (CVE-2024-4076, bsc#1228258)

Список пакетов

Image SLES15-SP5-Azure-3P
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Basic
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Standard
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-BYOS-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-CHOST-BYOS-Aliyun
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-CHOST-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-CHOST-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-CHOST-BYOS-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-CHOST-BYOS-GDC
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-CHOST-BYOS-SAP-CCloud
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-HPC-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-HPC-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-HPC-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-HPC-BYOS-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Hardened-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Hardened-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Hardened-BYOS-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Proxy-5-0-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0-Azure-llc
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0-Azure-ltd
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0-BYOS
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0-EC2-llc
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Manager-Server-5-0-EC2-ltd
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Micro-5-5
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Micro-5-5-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Micro-5-5-BYOS
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Micro-5-5-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Micro-5-5-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Micro-5-5-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Azure-3P
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Azure-LI-BYOS
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-BYOS-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Hardened-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAP-Hardened-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAPCAL-Azure
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAPCAL-EC2
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-SAPCAL-GCE
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
SUSE Linux Enterprise Micro 5.5
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1
SUSE Linux Enterprise Module for Server Applications 15 SP5
bind-9.16.50-150500.8.21.1
bind-doc-9.16.50-150500.8.21.1
openSUSE Leap 15.5
bind-9.16.50-150500.8.21.1
bind-doc-9.16.50-150500.8.21.1
bind-utils-9.16.50-150500.8.21.1
python3-bind-9.16.50-150500.8.21.1

Описание

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.


Затронутые продукты
Image SLES15-SP5-Azure-3P:bind-utils-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-3P:python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Basic:bind-utils-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Basic:python3-bind-9.16.50-150500.8.21.1

Ссылки

Описание

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.


Затронутые продукты
Image SLES15-SP5-Azure-3P:bind-utils-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-3P:python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Basic:bind-utils-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Basic:python3-bind-9.16.50-150500.8.21.1

Ссылки

Описание

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.


Затронутые продукты
Image SLES15-SP5-Azure-3P:bind-utils-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-3P:python3-bind-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Basic:bind-utils-9.16.50-150500.8.21.1
Image SLES15-SP5-Azure-Basic:python3-bind-9.16.50-150500.8.21.1

Ссылки
Уязвимость SUSE-SU-2024:2862-1