CVE-2024-12705: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
Other sources
Description: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
Impact: By flooding a target resolver with HTTP/2 traffic and exploiting this flaw, an attacker could overwhelm the server, causing high CPU and/or memory usage and preventing other clients from establishing DoH connections. This would significantly impair the resolver's performance and effectively deny legitimate clients access to the DNS resolution service.
Authoritative servers are affected by this vulnerability. Resolvers are affected by this vulnerability.
Versions affected: 9.18.0 -> 9.18.32 9.20.0 -> 9.20.4 9.21.0 -> 9.21.3
(Versions prior to 9.18.27 were not assessed.)
— Red Hat
DNS-over-HTTPS implementation suffers from multiple issues under heavy query load
— Debian
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.5-1 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.18.33 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.5 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.21.4 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.18.33-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12705?
CVE-2024-12705 has a medium severity rating as it can lead to resource exhaustion of the DNS resolver.
How do I fix CVE-2024-12705?
To fix CVE-2024-12705, you should upgrade BIND 9 to a version that is not affected, such as a version outside of the specified ranges.
Which BIND 9 versions are affected by CVE-2024-12705?
CVE-2024-12705 affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
What attack vector is associated with CVE-2024-12705?
CVE-2024-12705 can be exploited by flooding a DNS resolver with crafted HTTP/2 traffic, leading to potential CPU and memory exhaustion.
How can I mitigate the risks of CVE-2024-12705?
Mitigations for CVE-2024-12705 include applying rate limiting on DNS requests and ensuring that your DNS servers are running updated versions of BIND.