PT-2024-5529 · Isc+12 · Bind 9+12

·

CVE-2024-1975

·

Published

2024-07-23

·

Updated

2025-02-03

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.0.0 through 9.11.37 BIND 9 versions 9.16.0 through 9.16.50 BIND 9 versions 9.18.0 through 9.18.27 BIND 9 versions 9.19.0 through 9.19.24 BIND 9 versions 9.9.3-S1 through 9.11.37-S1 BIND 9 versions 9.16.8-S1 through 9.16.49-S1 BIND 9 versions 9.18.11-S1 through 9.18.27-S1
Description A client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests if a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache.
Recommendations For BIND 9 versions 9.0.0 through 9.11.37, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.16.0 through 9.16.50, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.18.0 through 9.18.27, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.19.0 through 9.19.24, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.9.3-S1 through 9.11.37-S1, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.16.8-S1 through 9.16.49-S1, update to a version outside of this range to resolve the issue. For BIND 9 versions 9.18.11-S1 through 9.18.27-S1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of SIG(0) signed requests to minimize the risk of exploitation.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:5231
ALSA-2024:5390
ALSA-2024:5524
ALT-PU-2024-12002
ALT-PU-2024-12367
ALT-PU-2024-12474
ALT-PU-2024-13685
ALT-PU-2025-2228
AZL-46969
AZL-47000
AZL-47039
BDU:2024-06188
CESA-2024_5390
CESA-2024_5524
CVE-2024-1975
DSA-5734-1
DSA-5734-2
INFSA-2024_5231
INFSA-2024_5390
INFSA-2024_5524
MGASA-2024-0342
OESA-2024-1969
OESA-2024-1970
OESA-2024-1971
OESA-2024-1972
OESA-2024-1973
OESA-2024-2390
OPENSUSE-SU-2024:14217-1
RHSA-2024:5231
RHSA-2024:5390
RHSA-2024:5418
RHSA-2024:5524
RHSA-2024:5525
RHSA-2024:5655
RHSA-2024:5813
RHSA-2024:5838
RHSA-2024:5871
RHSA-2024:5894
RHSA-2024:5907
RHSA-2024:5908
RHSA-2024:5930
RHSA-2024_5231
RHSA-2024_5390
RHSA-2024_5524
RLSA-2024:5231
ROSA-SA-2024-2514
SUSE-SU-2024:2636-1
SUSE-SU-2024:2810-1
SUSE-SU-2024:2811-1
SUSE-SU-2024:2862-1
SUSE-SU-2024:2863-1
SUSE-SU-2024:2868-1
USN-6909-1
USN-6909-2
USN-6909-3

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu