CVE Vulnerabilities

CVE-2023-4408

Published: Feb 13, 2024 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

Affected Software

Name Vendor Start Version End Version
Ontap Netapp 9.14.1 (including) 9.14.1 (including)
Ontap Netapp 9.15.1 (including) 9.15.1 (including)
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION RedHat bind-32:9.8.2-0.68.rc1.el6_10.14 *
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION RedHat bind-dyndb-ldap-0:2.3-8.el6_10.1 *
Red Hat Enterprise Linux 7 RedHat bind-32:9.11.4-26.P2.el7_9.16 *
Red Hat Enterprise Linux 7 RedHat bind-dyndb-ldap-0:11.1-7.el7_9.1 *
Red Hat Enterprise Linux 7 RedHat dhcp-12:4.2.5-83.el7_9.2 *
Red Hat Enterprise Linux 8 RedHat bind9.16-32:9.16.23-0.16.el8_9.2 *
Red Hat Enterprise Linux 8 RedHat bind-32:9.11.36-11.el8_9.1 *
Red Hat Enterprise Linux 8 RedHat bind-32:9.11.36-14.el8_10 *
Red Hat Enterprise Linux 8 RedHat bind-32:9.11.36-11.el8_9.1 *
Red Hat Enterprise Linux 8 RedHat bind-32:9.11.36-14.el8_10 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat bind-32:9.11.13-6.el8_2.7 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat dhcp-12:4.3.6-40.el8_2.3 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat bind-32:9.11.26-4.el8_4.4 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat dhcp-12:4.3.6-44.el8_4.3 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat bind-32:9.11.26-4.el8_4.4 *
Red Hat Enterprise Linux 8.4 Telecommunications Update Service RedHat dhcp-12:4.3.6-44.el8_4.3 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat bind-32:9.11.26-4.el8_4.4 *
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions RedHat dhcp-12:4.3.6-44.el8_4.3 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat bind9.16-32:9.16.23-0.7.el8_6.5 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat bind-32:9.11.36-3.el8_6.7 *
Red Hat Enterprise Linux 8.6 Extended Update Support RedHat dhcp-12:4.3.6-47.el8_6.2 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat bind9.16-32:9.16.23-0.14.el8_8.4 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat bind-32:9.11.36-8.el8_8.4 *
Red Hat Enterprise Linux 8.8 Extended Update Support RedHat dhcp-12:4.3.6-49.el8_8.1 *
Red Hat Enterprise Linux 9 RedHat bind-32:9.16.23-14.el9_3.4 *
Red Hat Enterprise Linux 9 RedHat bind-dyndb-ldap-0:11.9-8.el9_3.3 *
Red Hat Enterprise Linux 9 RedHat bind-32:9.16.23-18.el9_4.1 *
Red Hat Enterprise Linux 9 RedHat bind-dyndb-ldap-0:11.9-9.el9_4 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat bind-32:9.16.23-1.el9_0.5 *
Red Hat Enterprise Linux 9.0 Extended Update Support RedHat bind-dyndb-ldap-0:11.9-7.el9_0.1 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat bind-32:9.16.23-11.el9_2.4 *
Red Hat Enterprise Linux 9.2 Extended Update Support RedHat bind-dyndb-ldap-0:11.9-8.el9_2.2 *
Bind9 Ubuntu bionic *
Bind9 Ubuntu devel *
Bind9 Ubuntu esm-infra/xenial *
Bind9 Ubuntu focal *
Bind9 Ubuntu jammy *
Bind9 Ubuntu mantic *
Bind9 Ubuntu noble *
Bind9 Ubuntu oracular *
Bind9 Ubuntu trusty *
Bind9 Ubuntu trusty/esm *
Bind9 Ubuntu upstream *
Bind9 Ubuntu xenial *
Isc-dhcp Ubuntu mantic *

References