RHSA-2024:1648: Important: bind9.16 security update
Important: bind9.16 security update
Other sources
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind9.16: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind9.16: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) bind9.16: Specific recursive query patterns may lead to an out-of-memory condition (CVE-2023-6516) bind9.16: Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution (CVE-2023-5679) bind9.16: Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled (CVE-2023-5517) bind9.16: Parsing large DNS messages may cause excessive CPU load (CVE-2023-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-licenseto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/python3-bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-chrootto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-debugsourceto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-dnssec-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-libsto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-libs-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-utilsto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-utils-debuginfoto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-docto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4 - Upgrade
Upgrade
redhat/bind9.16-develto a version that resolves this vulnerability.Fixed in 9.16.23-0.14.el8_8.4.aa - Upgrade
Upgrade
bind9.16to a version that resolves this vulnerability.Fixed in bind9.16Patch CVE-2023-5679 - Upgrade
Upgrade
bind9.16to a version that resolves this vulnerability.Fixed in bind9.16Patch CVE-2023-4408 - Upgrade
Upgrade
bind9.16to a version that resolves this vulnerability.Fixed in bind9.16Patch CVE-2023-50868 - Upgrade
Upgrade
bind9.16to a version that resolves this vulnerability.Fixed in bind9.16Patch CVE-2023-5517 - Upgrade
Upgrade
bind9.16to a version that resolves this vulnerability.Fixed in bind9.16Patch CVE-2023-6516 - Upgrade
Upgrade
bind9.16to a version that resolves this vulnerability.Fixed in bind9.16Patch CVE-2023-50387
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1648?
The severity of RHSA-2024:1648 is classified as Important.
How do I fix RHSA-2024:1648?
To fix RHSA-2024:1648, you should update the bind9.16 package to version 9.16.23-0.14.el8_8.4.
What systems are affected by RHSA-2024:1648?
RHSA-2024:1648 affects various versions of Red Hat Enterprise Linux, including x86_64, ARM 64, and Power architectures.
What is BIND in the context of RHSA-2024:1648?
BIND refers to the Berkeley Internet Name Domain, which is an implementation of the Domain Name System (DNS) protocols.
What does the update for RHSA-2024:1648 include?
The update for RHSA-2024:1648 includes security patches and bug fixes for the BIND software.