RHSA-2024:1647: Important: bind9.16 security update
Important: bind9.16 security update
Other sources
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind9.16: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) bind9.16: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind9.16: Specific recursive query patterns may lead to an out-of-memory condition (CVE-2023-6516) bind9.16: Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution (CVE-2023-5679) bind9.16: Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled (CVE-2023-5517) bind9.16: bind9: Parsing large DNS messages may cause excessive CPU load (CVE-2023-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-licenseto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-docto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/python3-bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5 - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.7.el8_6.5.aa - Upgrade
Upgrade
BIND (named) bind9.16to a version that resolves this vulnerability.Fixed in bind9.16 - Compensating control
If you cannot immediately apply the bind9.16 security update, avoid enabling DNS64 and serve-stale together because this may cause an assertion failure during recursive resolution (CVE-2023-5679).
- Compensating control
If you cannot immediately apply the bind9.16 security update, mitigate KeyTrap risk by limiting exposure of the DNSSEC validator functionality; extreme CPU consumption can occur in DNSSEC validator (CVE-2023-50387).
- Compensating control
If you cannot immediately apply the bind9.16 security update, avoid querying RFC 1918 reverse zones while nxdomain-redirect is enabled, since this may cause an assertion failure (CVE-2023-5517).
- Compensating control
If you cannot immediately apply the bind9.16 security update, reduce exposure to specific recursive query patterns that may lead to an out-of-memory condition (CVE-2023-6516).
- Compensating control
If you cannot immediately apply the bind9.16 security update, protect the DNS service against large DNS messages that may cause excessive CPU load (CVE-2023-4408).
- Compensating control
If you cannot immediately apply the bind9.16 security update, mitigate the risk that preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) by restricting/monitoring traffic that triggers these proof-generation paths.
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1647?
The severity of RHSA-2024:1647 is classified as Important.
How do I fix RHSA-2024:1647?
To fix RHSA-2024:1647, update the affected bind9.16 package to version 9.16.23-0.7.el8_6.5.
Which versions of BIND are affected by RHSA-2024:1647?
RHSA-2024:1647 affects multiple versions of BIND as specified in the advisory for Red Hat Enterprise Linux product lines.
Is RHSA-2024:1647 related to DNS security?
Yes, RHSA-2024:1647 addresses security vulnerabilities in the Berkeley Internet Name Domain (BIND) related to DNS protocols.
What should I do if I cannot update to the recommended version for RHSA-2024:1647?
If you cannot update, consult Red Hat support for guidance on mitigating risks associated with the vulnerabilities identified in RHSA-2024:1647.