SB2024090978 - Denial of service in F5 BIG-IP DNS BIND component 



SB2024090978 - Denial of service in F5 BIG-IP DNS BIND component

Published: September 9, 2024

Security Bulletin ID SB2024090978
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Resource management error (CVE-ID: CVE-2024-1737)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application when handling a very large number of RRs. Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.