RHSA-2024:2551: Important: bind security update
Important: bind security update
Other sources
The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.Security Fix(es): bind: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (CVE-2023-50868) bind: KeyTrap - Extreme CPU consumption in DNSSEC validator (CVE-2023-50387) bind: Specific recursive query patterns may lead to an out-of-memory condition (CVE-2023-6516) bind: Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution (CVE-2023-5679) bind: Querying RFC 1918 reverse zones may cause an assertion failure when “nxdomain-redirect” is enabled (CVE-2023-5517) bind: Parsing large DNS messages may cause excessive CPU load (CVE-2023-4408) Bug Fix(es): bind-dyndb-ldap: rebuilt to adapt ABI changes in bind For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2551?
The severity of RHSA-2024:2551 is classified as important.
How do I fix RHSA-2024:2551?
To fix RHSA-2024:2551, update the affected packages to the versions specified in the advisory, such as bind 9.16.23-18.el9_4.1.
Which products are affected by RHSA-2024:2551?
Affected products include various versions of Red Hat Enterprise Linux and Red Hat CodeReady Linux Builder.
Is there a workaround for RHSA-2024:2551?
No specific workaround is provided for RHSA-2024:2551; the recommended action is to apply the updates.
What packages are associated with RHSA-2024:2551?
Packages associated with RHSA-2024:2551 include bind, bind-dyndb-ldap, and their related utilities and documentation.