RHSA-2022:6781: Important: bind9.16 security update
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly (CVE-2022-3080) bind: memory leak in ECDSA DNSSEC verification code (CVE-2022-38177) bind: memory leaks in EdDSA DNSSEC verification code (CVE-2022-38178) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-licenseto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-docto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/python3-bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.1.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:6781?
The severity of RHSA-2022:6781 is categorized as critical due to vulnerabilities within the BIND implementation.
How do I fix RHSA-2022:6781?
To fix RHSA-2022:6781, you need to update to version 9.16.23-0.7.el8_6.1 or later of the affected BIND packages.
Which software is affected by RHSA-2022:6781?
RHSA-2022:6781 affects various BIND9.16 packages including bind9.16, bind9.16-debuginfo, bind9.16-libs, and others.
Is documentation available for RHSA-2022:6781?
Yes, there is documentation related to RHSA-2022:6781 which provides details on the vulnerabilities and the remediation steps.
Where can I find more information on RHSA-2022:6781?
More information on RHSA-2022:6781 can be found in the advisories and bug reports related to the Red Hat security updates.