Resource management error in ISC BIND - CVE-2023-2911

 

Resource management error in ISC BIND - CVE-2023-2911

Published: June 21, 2023


Vulnerability identifier: #VU77610
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-2911
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the application. If the recursive-clients quota is reached on a BIND 9 resolver configured with both stale-answer-enable yes; and stale-answer-client-timeout 0;, a sequence of serve-stale-related lookups could cause named to loop and terminate unexpectedly due to a stack overflow.


Affected software

ISC BIND
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
Oracle Solaris
Ubuntu
Slackware Linux
Basesystem Module
Server Applications Module
openSUSE Leap
Fedora
VMware Tanzu Application Service for VMs
Isolation Segment
IBM Spectrum Conductor
IBM Spectrum Symphony
VMware Tanzu Operations Manager
bind9 (Ubuntu package)
bind
bind9 (Debian package)
bind-utils-debuginfo
bind-debuginfo
bind-debugsource
bind-utils
bind-doc
python3-bind
bind-dyndb-ldap
ObjectScale
Dell EMC VxRail Appliance

How to mitigate CVE-2023-2911

Install updates from vendor's website.

ISC BIND - addressed in versions 9.16.42-S1, 9.18.16, 9.18.16-S1, 9.19.14
VMware Tanzu Application Service for VMs - addressed in versions 2.11.44, 2.13.26, 3.0.16, 4.0.8
Isolation Segment - addressed in versions 2.11.38, 2.13.23, 3.0.16, 4.0.8
VMware Tanzu Operations Manager - addressed in versions 2.10.60, 3.0.12
bind9 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:9.16.1-0ubuntu2.15, 1:9.18.12-0ubuntu0.22.04.2, 1:9.18.12-0ubuntu0.22.10.2, 1:9.18.12-1ubuntu1.1
ObjectScale - update to 1.4.0
IBM Spectrum Conductor - update to 2.5.1 FP2
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
Dell EMC VxRail Appliance - update to 8.0.120
bind - update to 9.16.42
bind - update to 9.16.42-1
bind9 (Debian package) - addressed in versions 1:9.16.42-1~deb11u1, 1:9.18.16-1~deb12u1
bind - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-utils-debuginfo - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-debuginfo - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-debugsource - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-utils - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-doc - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
python3-bind - addressed in versions 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind - addressed in versions 9.18.16-1.fc37, 9.18.16-1.fc38, 9.18.16-1.fc39
bind-dyndb-ldap - addressed in versions 11.10-15.fc37, 11.10-17.fc38, 11.10-17.fc39

External References

Related Security Bulletins