RHSA-2024:1789: Important: bind security update
Important: bind security update
Other sources
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) bind: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind: Specific recursive query patterns may lead to an out-of-memory condition (CVE-2023-6516) bind: Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution (CVE-2023-5679) bind: Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled (CVE-2023-5517) bind: Parsing large DNS messages may cause excessive CPU load (CVE-2023-4408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:1789?
The severity of RHSA-2024:1789 is classified as Important.
How do I fix RHSA-2024:1789?
To fix RHSA-2024:1789, update your BIND packages to the latest version 9.16.23-14.el9_3.4 or 11.9-8.el9_3.3.
Which products are affected by RHSA-2024:1789?
RHSA-2024:1789 affects various Red Hat products including Red Hat Enterprise Linux and CodeReady Linux Builder on multiple architectures.
What issues does RHSA-2024:1789 address?
RHSA-2024:1789 addresses security vulnerabilities present in the BIND implementation of the DNS protocols.
Is there a specific version I need to upgrade to for RHSA-2024:1789?
Yes, you need to upgrade to version 9.16.23-14.el9_3.4 or 11.9-8.el9_3.3 to mitigate the identified vulnerabilities.