Resource exhaustion in ISC BIND - CVE-2023-2828

 

Resource exhaustion in ISC BIND - CVE-2023-2828

Published: June 21, 2023


Vulnerability identifier: #VU77612
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-2828
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can cause the amount of memory used by a named resolver to go well beyond the configured max-cache-size limit. The effectiveness of the attack depends on a number of factors (e.g. query load, query patterns), but since the default value of the max-cache-size statement is 90%, in the worst case the attacker can exhaust all available memory on the host running named, leading to a denial-of-service condition.


Affected software

ISC BIND
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux Server
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
Ubuntu
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Pak for Business Automation
Netcool Operations Insight
IBM Spectrum Conductor
Session Smart Router
IBM Spectrum Symphony
IBM Robotic Process Automation
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
ObjectScale
Storage Defender – Data Protect
EMC ECS
IBM Cloud Pak for Watson AIOps
XtremIO X2
Index Engines CyberSense
EMC Cloud Tiering Appliance
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Multicluster Engine for Kubernetes
OpenShift Service Mesh
VMware Tanzu Operations Manager
OpenShift Virtualization
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bind9 (Ubuntu package)
bind-doc
bind-libs
bind-libs-debuginfo-32bit
bind-libs-32bit
bind-utils-debuginfo
bind-utils
bind-libs-debuginfo
bind-debugsource
bind
bind-debuginfo
bind-chrootenv
bind-chroot
bind-export-devel
bind-devel
bind-export-libs
bind-libs-lite
bind-lite-devel
bind-pkcs11
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind-pkcs11-devel
bind-license
bind (Red Hat package) main
python3-bind
libbind9-161-debuginfo
liblwres161-debuginfo
libisc1107-debuginfo
libisccfg163
libisc1107-32bit
libisccc161
libirs161
libisc1107-debuginfo-32bit
libisccfg163-debuginfo
libirs161-debuginfo
libdns1110
libisc1107
libdns1110-debuginfo
libbind9-161
python-bind
libisccc161-debuginfo
liblwres161
libisc1606
libns1604-debuginfo
libirs1601-32bit-debuginfo
libisccc1600-64bit
libdns1605-64bit
libirs1601-64bit
libisc1606-64bit
libbind9-1600-64bit
libisccfg1600-64bit
libirs1601-32bit
libisccc1600-32bit
libns1604-32bit
libisc1606-32bit
libisc1606-32bit-debuginfo
libbind9-1600
libdns1605-debuginfo
libisccc1600
libns1604
libisccfg1600-debuginfo
libirs1601-debuginfo
libirs1601
libns1604-32bit-debuginfo
libisc1606-debuginfo
libisccc1600-debuginfo
libisccfg1600
libirs-devel
libbind9-1600-debuginfo
libbind9-1600-32bit-debuginfo
libisccfg1600-32bit
bind-devel-32bit
libisccc1600-32bit-debuginfo
libisccfg1600-32bit-debuginfo
libbind9-1600-32bit
libdns1605
libdns1605-32bit-debuginfo
libdns1605-32bit
bind9.16 (Red Hat package)
bind9.16
bind9.16-chroot
bind9.16-dnssec-utils
bind9.16-libs
bind9.16-utils
bind9.16-doc
bind9.16-license
python3-bind9.16
bind-dnssec-utils
bind-dnssec-doc
bind9 (Debian package)
bind-dyndb-ldap
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
RecoverPoint for VMs
IBM QRadar Network Packet Capture
IBM Integrated Analytics System
Dell EMC VxRail Appliance
Operational Decision Manager

How to mitigate CVE-2023-2828

Install updates from vendor's website.

ISC BIND - addressed in versions 9.16.42, 9.16.42-S1, 9.18.16, 9.18.16-S1, 9.19.14
Isolation Segment - addressed in versions 2.11.38, 2.13.23, 3.0.16, 4.0.8
VMware Tanzu Application Service for VMs - addressed in versions 2.11.44, 2.13.26, 3.0.16, 4.0.8
Migration Toolkit for Containers - update to 1.7.12
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7
OpenShift Service Mesh - addressed in versions 2.3.6, 2.4.2
VMware Tanzu Operations Manager - addressed in versions 2.10.60, 3.0.12
Red Hat OpenShift Container Platform - addressed in versions 4.11.46, 4.13.6
OpenShift Virtualization - addressed in versions 4.11.6, 4.12.5
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
bind9 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:9.16.1-0ubuntu2.15, 1:9.18.12-0ubuntu0.22.04.2, 1:9.18.12-0ubuntu0.22.10.2, 1:9.18.12-1ubuntu1.1
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Spectrum Conductor - update to 2.5.1 FP2
EMC ECS - update to 3.8.0.4
IBM Cloud Pak for Watson AIOps - update to 4.2.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
XtremIO X2 - update to 6.4.2-13
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 7
IBM Integrated Analytics System - update to 7.9.23.08.SP21
Dell EMC VxRail Appliance - update to 8.0.120
Index Engines CyberSense - update to 8.4
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 49, 8.11.0.1 Interim fix 26, 8.12.0 Interim fix 8
bind-doc - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-libs - update to 9.9.9P1-63.40.1
bind-libs-debuginfo-32bit - update to 9.9.9P1-63.40.1
bind-libs-32bit - update to 9.9.9P1-63.40.1
bind-utils-debuginfo - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-utils - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-libs-debuginfo - update to 9.9.9P1-63.40.1
bind-debugsource - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-debuginfo - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-chrootenv - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
bind - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind (Red Hat package) main - addressed in versions 9.11.4-26.P2.el7_9.14, 9.11.4-26.P2.el8_1.7, 9.11.13-6.el8_2.5, 9.11.26-4.el8_4.2, 9.11.36-3.el8_6.4, 9.11.36-8.el8_8.1, 9.16.23-1.el9_0.2, 9.16.23-11.el9_2.1
bind-debugsource - addressed in versions 9.11.21-16, 9.16.23-18
bind - addressed in versions 9.11.21-16, 9.16.23-18
bind-pkcs11 - addressed in versions 9.11.21-16, 9.16.23-18
bind-debuginfo - addressed in versions 9.11.21-16, 9.16.23-18
python3-bind - addressed in versions 9.11.21-16, 9.16.23-18
bind-utils - addressed in versions 9.11.21-16, 9.16.23-18
bind-devel - addressed in versions 9.11.21-16, 9.16.23-18
bind-export-libs - update to 9.11.21-16
bind-pkcs11-devel - addressed in versions 9.11.21-16, 9.16.23-18
bind-libs - addressed in versions 9.11.21-16, 9.16.23-18
bind-libs-lite - update to 9.11.21-16
bind-chroot - addressed in versions 9.11.21-16, 9.16.23-18
bind-export-devel - update to 9.11.21-16
libbind9-161-debuginfo - update to 9.11.22-3.46.4
liblwres161-debuginfo - update to 9.11.22-3.46.4
libisc1107-debuginfo - update to 9.11.22-3.46.4
libisccfg163 - update to 9.11.22-3.46.4
libisc1107-32bit - update to 9.11.22-3.46.4
libisccc161 - update to 9.11.22-3.46.4
libirs161 - update to 9.11.22-3.46.4
libisc1107-debuginfo-32bit - update to 9.11.22-3.46.4
libisccfg163-debuginfo - update to 9.11.22-3.46.4
libirs161-debuginfo - update to 9.11.22-3.46.4
libdns1110 - update to 9.11.22-3.46.4
libisc1107 - update to 9.11.22-3.46.4
libdns1110-debuginfo - update to 9.11.22-3.46.4
libbind9-161 - update to 9.11.22-3.46.4
bind-devel - addressed in versions 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
python-bind - update to 9.11.22-3.46.4
libisccc161-debuginfo - update to 9.11.22-3.46.4
liblwres161 - update to 9.11.22-3.46.4
python3-bind - update to 9.11.36-8
libisc1606 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs1601-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisccc1600-64bit - update to 9.16.6-150000.12.68.1
libdns1605-64bit - update to 9.16.6-150000.12.68.1
libirs1601-64bit - update to 9.16.6-150000.12.68.1
libisc1606-64bit - update to 9.16.6-150000.12.68.1
libbind9-1600-64bit - update to 9.16.6-150000.12.68.1
libisccfg1600-64bit - update to 9.16.6-150000.12.68.1
libirs1601-32bit - update to 9.16.6-150000.12.68.1
libisccc1600-32bit - update to 9.16.6-150000.12.68.1
libns1604-32bit - update to 9.16.6-150000.12.68.1
libisc1606-32bit - update to 9.16.6-150000.12.68.1
libisc1606-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccc1600 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libns1604 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs1601 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libns1604-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs-devel - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
python3-bind - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
libbind9-1600-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisccfg1600-32bit - update to 9.16.6-150000.12.68.1
bind-devel-32bit - update to 9.16.6-150000.12.68.1
libisccc1600-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisccfg1600-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libbind9-1600-32bit - update to 9.16.6-150000.12.68.1
libdns1605 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libdns1605-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libdns1605-32bit - update to 9.16.6-150000.12.68.1
bind9.16 (Red Hat package) - addressed in versions 9.16.23-0.7.el8_6.2, 9.16.23-0.14.el8_8.1
bind9.16 - update to 9.16.23-0.14
bind9.16-chroot - update to 9.16.23-0.14
bind9.16-dnssec-utils - update to 9.16.23-0.14
bind9.16-libs - update to 9.16.23-0.14
bind9.16-utils - update to 9.16.23-0.14
bind9.16-doc - update to 9.16.23-0.14
bind9.16-license - update to 9.16.23-0.14
python3-bind9.16 - update to 9.16.23-0.14
bind-pkcs11-utils - update to 9.16.23-18
bind-dnssec-utils - update to 9.16.23-18
bind-dnssec-doc - update to 9.16.23-18
bind-license - update to 9.16.23-18
bind-pkcs11-libs - update to 9.16.23-18
bind - update to 9.16.42-1
bind9 (Debian package) - addressed in versions 1:9.16.42-1~deb11u1, 1:9.18.16-1~deb12u1
bind - addressed in versions 9.18.16-1.fc37, 9.18.16-1.fc38, 9.18.16-1.fc39
bind-dyndb-ldap - addressed in versions 11.10-15.fc37, 11.10-17.fc38, 11.10-17.fc39
EMC Cloud Tiering Appliance - addressed in versions 13.1.0.2.33, 13.2.0.2.24
IBM Robotic Process Automation - addressed in versions 21.0.7.8, 23.0.9

External References

Related Security Bulletins