Resource management error in ISC BIND - CVE-2023-2911
Published: June 21, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application. If the recursive-clients quota is reached on a BIND 9 resolver configured with both stale-answer-enable yes; and stale-answer-client-timeout 0;, a sequence of serve-stale-related lookups could cause named to loop and terminate unexpectedly due to a stack overflow.
Affected software
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Oracle Solaris
Ubuntu
Slackware Linux
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
IBM Spectrum Conductor
IBM Spectrum Symphony
VMware Tanzu Operations Manager
bind9 (Ubuntu package)
bind
bind9 (Debian package)
bind-utils-debuginfo
bind-debuginfo
bind-debugsource
bind-utils
bind-doc
python3-bind
bind-dyndb-ldap
ObjectScale
Dell EMC VxRail Appliance
How to mitigate CVE-2023-2911
VMware Tanzu Application Service for VMs - addressed in versions 2.11.44, 2.13.26, 3.0.16, 4.0.8
Isolation Segment - addressed in versions 2.11.38, 2.13.23, 3.0.16, 4.0.8
VMware Tanzu Operations Manager - addressed in versions 2.10.60, 3.0.12
bind9 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:9.16.1-0ubuntu2.15, 1:9.18.12-0ubuntu0.22.04.2, 1:9.18.12-0ubuntu0.22.10.2, 1:9.18.12-1ubuntu1.1
ObjectScale - update to 1.4.0
IBM Spectrum Conductor - update to 2.5.1 FP2
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
Dell EMC VxRail Appliance - update to 8.0.120
bind - update to 9.16.42
bind - update to 9.16.42-1
bind9 (Debian package) - addressed in versions 1:9.16.42-1~deb11u1, 1:9.18.16-1~deb12u1
bind - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-utils-debuginfo - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-debuginfo - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-debugsource - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-utils - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-doc - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
python3-bind - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind - addressed in versions 9.18.16-1.fc37, 9.18.16-1.fc38, 9.18.16-1.fc39
bind-dyndb-ldap - addressed in versions 11.10-15.fc37, 11.10-17.fc38, 11.10-17.fc39
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Ubuntu update for bind9
- Slackware Linux update for bind
- Debian update for bind9
- SUSE update for bind
- SUSE update for bind
- Ubuntu update for bind9
- VMware Tanzu products update for Bind
- Fedora 39 update for bind, bind-dyndb-ldap
- Fedora 38 update for bind, bind-dyndb-ldap
- Fedora 37 update for bind, bind-dyndb-ldap
- Multiple vulnerabilities in Oracle Solaris third-party software
- Resource management error in IBM Spectrum Conductor
- Multiple vulnerabilities in IBM Spectrum Symphony
- VMware Tanzu update for Bind
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Dell ObjectScale
- Amazon Linux AMI update for bind