REDHAT-BUG-2298901: High severity ISC BIND9 vulnerability
If a server hosts a zone containing a “KEY” Resource Record, or a resolver DNSSEC-validates a “KEY” Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests.
This vulnerability affects the following upstream's bind9 versions: 9.0.0 -> 9.11.37 9.16.0 -> 9.16.50 9.18.0 -> 9.18.27 9.19.0 -> 9.19.24
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2298901?
The severity of REDHAT-BUG-2298901 is classified as high due to the potential for CPU resource exhaustion.
How do I fix REDHAT-BUG-2298901?
To mitigate REDHAT-BUG-2298901, you should upgrade to the latest version of ISC BIND9 that is not affected by this vulnerability.
Which versions of BIND9 are affected by REDHAT-BUG-2298901?
Versions of BIND9 from 9.0.0 to 9.11.37, 9.16.0 to 9.16.50, 9.18.0 to 9.18.27, and 9.19.0 to 9.19.24 are affected by REDHAT-BUG-2298901.
What does REDHAT-BUG-2298901 exploit?
REDHAT-BUG-2298901 exploits the processing of SIG(0) signed requests from a client against a zone containing a KEY Resource Record.
What should I monitor after addressing REDHAT-BUG-2298901?
After addressing REDHAT-BUG-2298901, monitor for any abnormal CPU usage patterns in your DNS resolver to detect potential abuse.