REDHAT-BUG-2451305: High severity ISC BIND 9 vulnerability
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2451305?
The severity of REDHAT-BUG-2451305 is classified as moderate due to potential CPU exhaustion from maliciously crafted DNS zones.
How do I fix REDHAT-BUG-2451305?
To fix REDHAT-BUG-2451305, upgrade to a patched version of ISC BIND 9 that is not affected by this vulnerability.
Which versions of ISC BIND 9 are affected by REDHAT-BUG-2451305?
REDHAT-BUG-2451305 affects ISC BIND 9 versions from 9.11.0 to 9.16.50 and multiple others within specific ranges.
What is the impact of REDHAT-BUG-2451305 on DNS resolvers?
The impact of REDHAT-BUG-2451305 on DNS resolvers is excessive CPU consumption when processing malicious DNSSEC validation requests.
Are authoritative-only servers affected by REDHAT-BUG-2451305?
Authoritative-only servers are generally unaffected but may still be vulnerable in certain circumstances that involve recursive queries.