CVE Vulnerabilities

CVE-2023-4408

Published: Feb 13, 2024 | Modified: Mar 14, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

Affected Software

NameVendorStart VersionEnd Version
OntapNetapp9.14.1 (including)9.14.1 (including)
OntapNetapp9.15.1 (including)9.15.1 (including)
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONRedHatbind-32:9.8.2-0.68.rc1.el6_10.14*
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONRedHatbind-dyndb-ldap-0:2.3-8.el6_10.1*
Red Hat Enterprise Linux 7RedHatbind-32:9.11.4-26.P2.el7_9.16*
Red Hat Enterprise Linux 7RedHatbind-dyndb-ldap-0:11.1-7.el7_9.1*
Red Hat Enterprise Linux 7RedHatdhcp-12:4.2.5-83.el7_9.2*
Red Hat Enterprise Linux 8RedHatbind9.16-32:9.16.23-0.16.el8_9.2*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-11.el8_9.1*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-14.el8_10*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-11.el8_9.1*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-14.el8_10*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatbind-32:9.11.13-6.el8_2.7*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatdhcp-12:4.3.6-40.el8_2.3*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatbind-32:9.11.26-4.el8_4.4*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatdhcp-12:4.3.6-44.el8_4.3*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatbind-32:9.11.26-4.el8_4.4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatdhcp-12:4.3.6-44.el8_4.3*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatbind-32:9.11.26-4.el8_4.4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatdhcp-12:4.3.6-44.el8_4.3*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatbind9.16-32:9.16.23-0.7.el8_6.5*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatbind-32:9.11.36-3.el8_6.7*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatdhcp-12:4.3.6-47.el8_6.2*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatbind9.16-32:9.16.23-0.14.el8_8.4*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatbind-32:9.11.36-8.el8_8.4*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatdhcp-12:4.3.6-49.el8_8.1*
Red Hat Enterprise Linux 9RedHatbind-32:9.16.23-14.el9_3.4*
Red Hat Enterprise Linux 9RedHatbind-dyndb-ldap-0:11.9-8.el9_3.3*
Red Hat Enterprise Linux 9RedHatbind-32:9.16.23-18.el9_4.1*
Red Hat Enterprise Linux 9RedHatbind-dyndb-ldap-0:11.9-9.el9_4*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatbind-32:9.16.23-1.el9_0.5*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatbind-dyndb-ldap-0:11.9-7.el9_0.1*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatbind-32:9.16.23-11.el9_2.4*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatbind-dyndb-ldap-0:11.9-8.el9_2.2*
Bind9Ubuntubionic*
Bind9Ubuntudevel*
Bind9Ubuntuesm-infra-legacy/trusty*
Bind9Ubuntuesm-infra/bionic*
Bind9Ubuntuesm-infra/focal*
Bind9Ubuntuesm-infra/xenial*
Bind9Ubuntufocal*
Bind9Ubuntujammy*
Bind9Ubuntumantic*
Bind9Ubuntunoble*
Bind9Ubuntuoracular*
Bind9Ubuntuplucky*
Bind9Ubuntuquesting*
Bind9Ubuntutrusty*
Bind9Ubuntutrusty/esm*
Bind9Ubuntuupstream*
Bind9Ubuntuxenial*
Bind9-libsUbuntufocal*
Isc-dhcpUbuntumantic*
Isc-dhcpUbuntuoracular*
Isc-dhcpUbuntuplucky*

References