RHSA-2022:6780: Important: bind security update
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind: memory leak in ECDSA DNSSEC verification code (CVE-2022-38177) bind: memory leaks in EdDSA DNSSEC verification code (CVE-2022-38178) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-chrootto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-debugsourceto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-export-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-export-libsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-export-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-libsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-libs-liteto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-libs-lite-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-licenseto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-lite-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-pkcs11to a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-pkcs11-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-pkcs11-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-pkcs11-libsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-pkcs11-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-pkcs11-utilsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-pkcs11-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-sdbto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-sdb-chrootto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-sdb-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-utilsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bind-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/python3-bindto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-chrootto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-debugsourceto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-export-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-export-libsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-export-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-libsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-libs-liteto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-libs-lite-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-lite-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-pkcs11to a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-pkcs11-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-pkcs11-develto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-pkcs11-libsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-pkcs11-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-pkcs11-utilsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-pkcs11-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-sdbto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-sdb-chrootto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-sdb-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-utilsto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
redhat/bind-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.aa - Upgrade
Upgrade
bindto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.x86_64.rpmPatch bind-9.11.13-6.el8_2.4.x86_64.rpm - Upgrade
Upgrade
bindto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.ppc64le.rpmPatch bind-9.11.13-6.el8_2.4.ppc64le.rpm - Upgrade
Upgrade
bind-chrootto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.x86_64.rpmPatch bind-chroot-9.11.13-6.el8_2.4.x86_64.rpm - Upgrade
Upgrade
bind-chrootto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.ppc64le.rpmPatch bind-chroot-9.11.13-6.el8_2.4.ppc64le.rpm - Upgrade
Upgrade
python3-bindto a version that resolves this vulnerability.Fixed in 9.11.13-6.el8_2.4.noarch.rpmPatch python3-bind-9.11.13-6.el8_2.4.noarch.rpm
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6780?
The severity of RHSA-2022:6780 is classified as important.
How do I fix RHSA-2022:6780?
To fix RHSA-2022:6780, you should update to the packages specified in the advisory, particularly version 9.11.13-6.el8_2.4 of BIND.
What vulnerabilities does RHSA-2022:6780 address?
RHSA-2022:6780 addresses multiple vulnerabilities affecting the Berkeley Internet Name Domain (BIND) software.
Which versions of BIND are affected by RHSA-2022:6780?
RHSA-2022:6780 affects BIND versions prior to 9.11.13-6.el8_2.4.
Is it safe to ignore the updates provided in RHSA-2022:6780?
It is not safe to ignore the updates in RHSA-2022:6780 as it addresses significant security vulnerabilities.