REDHAT-BUG-2451310: High severity ISC BIND 9 vulnerability
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.20 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.21.19 - Upgrade
Upgrade
BIND 9to a version that resolves this vulnerability.Fixed in 9.20.20-S1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2451310?
The severity of REDHAT-BUG-2451310 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2451310?
To fix REDHAT-BUG-2451310, update to the latest versions of BIND 9 that have addressed this vulnerability.
What is the impact of REDHAT-BUG-2451310 on BIND resolvers?
REDHAT-BUG-2451310 can cause a memory leak in BIND resolvers simply by querying a specially crafted domain.
Which versions of BIND 9 are affected by REDHAT-BUG-2451310?
The affected versions of BIND 9 include 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1.
What should I do if I am using an affected version of BIND 9?
If you are using an affected version of BIND 9, you should upgrade to a patched version as soon as possible to mitigate the risk.