RHSA-2024:1781: Important: bind9.16 security update
Important: bind9.16 security update
Other sources
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind9: Parsing large DNS messages may cause excessive CPU load (CVE-2023-4408) bind9: Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled (CVE-2023-5517) bind9: Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution (CVE-2023-5679) bind9: Specific recursive query patterns may lead to an out-of-memory condition (CVE-2023-6516) bind9: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1781?
The severity of RHSA-2024:1781 is classified as important.
How do I fix RHSA-2024:1781?
To fix RHSA-2024:1781, update the bind9.16 package to version 9.16.23-0.16.el8_9.2.
Which Red Hat products are affected by RHSA-2024:1781?
RHSA-2024:1781 affects Red Hat Enterprise Linux for x86_64, ARM 64, Power, and IBM z Systems.
What components are included in the BIND implementation mentioned in RHSA-2024:1781?
The BIND implementation includes a DNS server, a resolver library, and tools for verifying DNS operations.
Is there a recommended action for users running older versions of BIND due to RHSA-2024:1781?
Yes, users should upgrade to the latest version to mitigate the vulnerabilities addressed in RHSA-2024:1781.