CVE-2023-4408: Parsing large DNS messages may cause excessive CPU load
Last updated 24 July 2024
Other sources
The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
— MITRE
The DNS message parsing code in named includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected named instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers.
— Red Hat
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4408?
CVE-2023-4408 has a moderate severity rating due to its potential to cause excessive CPU load under crafted DNS queries.
How do I fix CVE-2023-4408?
You can mitigate CVE-2023-4408 by upgrading to the recommended versions of BIND, specifically 9.16.50 or higher, 9.18.28 or higher, or 9.19.21.
Which software is affected by CVE-2023-4408?
CVE-2023-4408 affects various versions of BIND, F5 BIG-IP, F5 BIG-IQ Centralized Management, and specific versions of NetApp ONTAP.
What impact can CVE-2023-4408 have on my system?
If exploited, CVE-2023-4408 can lead to performance degradation due to increased CPU usage on affected DNS servers.
Is there a specific environment where CVE-2023-4408 is more critical?
CVE-2023-4408 is particularly critical in environments with high DNS query volumes or custom query configurations.