RHSA-2024:1334: Important: dnsmasq security update
Important: dnsmasq security update
Other sources
The dnsmasq packages contain Dnsmasq, a lightweight DNS (Domain Name Server) forwarder and DHCP (Dynamic Host Configuration Protocol) server.Security Fix(es): dnsmasq: bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) dnsmasq: bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868)For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1334?
RHSA-2024:1334 is classified as important due to the potential for extreme CPU consumption in DNSSEC validation.
How do I fix RHSA-2024:1334?
To fix RHSA-2024:1334, update the dnsmasq package to version 2.85-14.el9_3.1 or later.
Which systems are affected by RHSA-2024:1334?
RHSA-2024:1334 affects Red Hat Enterprise Linux for IBM z Systems, ARM 64, x86_64, and Power architectures.
What are the main vulnerabilities addressed in RHSA-2024:1334?
The main vulnerability addressed is the extreme CPU consumption in DNSSEC validation due to a flaw in dnsmasq.
Is a reboot required after updating to resolve RHSA-2024:1334?
A reboot is not typically required after updating dnsmasq for RHSA-2024:1334, but it is recommended to check specific application behavior.