Resource exhaustion in ISC BIND - CVE-2023-2828
Published: June 21, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can cause the amount of memory used by a named resolver to go well beyond the configured max-cache-size limit. The effectiveness of the attack depends on a number of factors (e.g. query load, query patterns), but since the default value of the max-cache-size statement is 90%, in the worst case the attacker can exhaust all available memory on the host running named, leading to a denial-of-service condition.
Affected software
Amazon Linux AMI
Debian Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
Anolis OS
Red Hat Enterprise Linux Server
CentOS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
Ubuntu
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
IBM Cloud Pak for Business Automation
Netcool Operations Insight
IBM Spectrum Conductor
Session Smart Router
IBM Spectrum Symphony
IBM Robotic Process Automation
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
ObjectScale
Storage Defender – Data Protect
EMC ECS
IBM Cloud Pak for Watson AIOps
XtremIO X2
Index Engines CyberSense
EMC Cloud Tiering Appliance
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Multicluster Engine for Kubernetes
OpenShift Service Mesh
VMware Tanzu Operations Manager
OpenShift Virtualization
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bind9 (Ubuntu package)
bind-doc
bind-libs
bind-libs-debuginfo-32bit
bind-libs-32bit
bind-utils-debuginfo
bind-utils
bind-libs-debuginfo
bind-debugsource
bind
bind-debuginfo
bind-chrootenv
bind-chroot
bind-export-devel
bind-devel
bind-export-libs
bind-libs-lite
bind-lite-devel
bind-pkcs11
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind-pkcs11-devel
bind-license
bind (Red Hat package) main
python3-bind
libbind9-161-debuginfo
liblwres161-debuginfo
libisc1107-debuginfo
libisccfg163
libisc1107-32bit
libisccc161
libirs161
libisc1107-debuginfo-32bit
libisccfg163-debuginfo
libirs161-debuginfo
libdns1110
libisc1107
libdns1110-debuginfo
libbind9-161
python-bind
libisccc161-debuginfo
liblwres161
libisc1606
libns1604-debuginfo
libirs1601-32bit-debuginfo
libisccc1600-64bit
libdns1605-64bit
libirs1601-64bit
libisc1606-64bit
libbind9-1600-64bit
libisccfg1600-64bit
libirs1601-32bit
libisccc1600-32bit
libns1604-32bit
libisc1606-32bit
libisc1606-32bit-debuginfo
libbind9-1600
libdns1605-debuginfo
libisccc1600
libns1604
libisccfg1600-debuginfo
libirs1601-debuginfo
libirs1601
libns1604-32bit-debuginfo
libisc1606-debuginfo
libisccc1600-debuginfo
libisccfg1600
libirs-devel
libbind9-1600-debuginfo
libbind9-1600-32bit-debuginfo
libisccfg1600-32bit
bind-devel-32bit
libisccc1600-32bit-debuginfo
libisccfg1600-32bit-debuginfo
libbind9-1600-32bit
libdns1605
libdns1605-32bit-debuginfo
libdns1605-32bit
bind9.16 (Red Hat package)
bind9.16
bind9.16-chroot
bind9.16-dnssec-utils
bind9.16-libs
bind9.16-utils
bind9.16-doc
bind9.16-license
python3-bind9.16
bind-dnssec-utils
bind-dnssec-doc
bind9 (Debian package)
bind-dyndb-ldap
Dell EMC Storage Monitoring and Reporting (SMR)
EMC ViPR SRM
RecoverPoint for VMs
IBM QRadar Network Packet Capture
IBM Integrated Analytics System
Dell EMC VxRail Appliance
Operational Decision Manager
How to mitigate CVE-2023-2828
Isolation Segment - addressed in versions 2.11.38, 2.13.23, 3.0.16, 4.0.8
VMware Tanzu Application Service for VMs - addressed in versions 2.11.44, 2.13.26, 3.0.16, 4.0.8
Migration Toolkit for Containers - update to 1.7.12
Multicluster Engine for Kubernetes - addressed in versions 2.1.8, 2.2.7
OpenShift Service Mesh - addressed in versions 2.3.6, 2.4.2
VMware Tanzu Operations Manager - addressed in versions 2.10.60, 3.0.12
Red Hat OpenShift Container Platform - addressed in versions 4.11.46, 4.13.6
OpenShift Virtualization - addressed in versions 4.11.6, 4.12.5
IBM Qradar SIEM - update to 7.5.0 Update Pack 7
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.26, 23.0.1.4
bind9 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:9.16.1-0ubuntu2.15, 1:9.18.12-0ubuntu0.22.04.2, 1:9.18.12-0ubuntu0.22.10.2, 1:9.18.12-1ubuntu1.1
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 1.4.0
Netcool Operations Insight - update to 1.6.11
IBM Spectrum Conductor - update to 2.5.1 FP2
EMC ECS - update to 3.8.0.4
IBM Cloud Pak for Watson AIOps - update to 4.2.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.0
EMC ViPR SRM - update to 4.10.0.0
RecoverPoint for VMs - update to 6.0.SP1.P1
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
XtremIO X2 - update to 6.4.2-13
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
IBM QRadar Network Packet Capture - update to 7.5.0 Update Package 7
IBM Integrated Analytics System - update to 7.9.23.08.SP21
Dell EMC VxRail Appliance - update to 8.0.120
Index Engines CyberSense - update to 8.4
Operational Decision Manager - addressed in versions 8.10.5.1 Interim fix 49, 8.11.0.1 Interim fix 26, 8.12.0 Interim fix 8
bind-doc - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-libs - update to 9.9.9P1-63.40.1
bind-libs-debuginfo-32bit - update to 9.9.9P1-63.40.1
bind-libs-32bit - update to 9.9.9P1-63.40.1
bind-utils-debuginfo - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-utils - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-libs-debuginfo - update to 9.9.9P1-63.40.1
bind-debugsource - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-debuginfo - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
bind-chrootenv - addressed in versions 9.9.9P1-63.40.1, 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
bind - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind (Red Hat package) main - addressed in versions 9.11.4-26.P2.el7_9.14, 9.11.4-26.P2.el8_1.7, 9.11.13-6.el8_2.5, 9.11.26-4.el8_4.2, 9.11.36-3.el8_6.4, 9.11.36-8.el8_8.1, 9.16.23-1.el9_0.2, 9.16.23-11.el9_2.1
bind-debugsource - addressed in versions 9.11.21-16, 9.16.23-18
bind - addressed in versions 9.11.21-16, 9.16.23-18
bind-pkcs11 - addressed in versions 9.11.21-16, 9.16.23-18
bind-debuginfo - addressed in versions 9.11.21-16, 9.16.23-18
python3-bind - addressed in versions 9.11.21-16, 9.16.23-18
bind-utils - addressed in versions 9.11.21-16, 9.16.23-18
bind-devel - addressed in versions 9.11.21-16, 9.16.23-18
bind-export-libs - update to 9.11.21-16
bind-pkcs11-devel - addressed in versions 9.11.21-16, 9.16.23-18
bind-libs - addressed in versions 9.11.21-16, 9.16.23-18
bind-libs-lite - update to 9.11.21-16
bind-chroot - addressed in versions 9.11.21-16, 9.16.23-18
bind-export-devel - update to 9.11.21-16
libbind9-161-debuginfo - update to 9.11.22-3.46.4
liblwres161-debuginfo - update to 9.11.22-3.46.4
libisc1107-debuginfo - update to 9.11.22-3.46.4
libisccfg163 - update to 9.11.22-3.46.4
libisc1107-32bit - update to 9.11.22-3.46.4
libisccc161 - update to 9.11.22-3.46.4
libirs161 - update to 9.11.22-3.46.4
libisc1107-debuginfo-32bit - update to 9.11.22-3.46.4
libisccfg163-debuginfo - update to 9.11.22-3.46.4
libirs161-debuginfo - update to 9.11.22-3.46.4
libdns1110 - update to 9.11.22-3.46.4
libisc1107 - update to 9.11.22-3.46.4
libdns1110-debuginfo - update to 9.11.22-3.46.4
libbind9-161 - update to 9.11.22-3.46.4
bind-devel - addressed in versions 9.11.22-3.46.4, 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
python-bind - update to 9.11.22-3.46.4
libisccc161-debuginfo - update to 9.11.22-3.46.4
liblwres161 - update to 9.11.22-3.46.4
python3-bind - update to 9.11.36-8
libisc1606 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs1601-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisccc1600-64bit - update to 9.16.6-150000.12.68.1
libdns1605-64bit - update to 9.16.6-150000.12.68.1
libirs1601-64bit - update to 9.16.6-150000.12.68.1
libisc1606-64bit - update to 9.16.6-150000.12.68.1
libbind9-1600-64bit - update to 9.16.6-150000.12.68.1
libisccfg1600-64bit - update to 9.16.6-150000.12.68.1
libirs1601-32bit - update to 9.16.6-150000.12.68.1
libisccc1600-32bit - update to 9.16.6-150000.12.68.1
libns1604-32bit - update to 9.16.6-150000.12.68.1
libisc1606-32bit - update to 9.16.6-150000.12.68.1
libisc1606-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccc1600 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libns1604 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs1601 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libns1604-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libirs-devel - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
python3-bind - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1, 9.16.42-150400.5.27.1, 9.16.42-150500.8.3.1
libbind9-1600-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisccfg1600-32bit - update to 9.16.6-150000.12.68.1
bind-devel-32bit - update to 9.16.6-150000.12.68.1
libisccc1600-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libisccfg1600-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libbind9-1600-32bit - update to 9.16.6-150000.12.68.1
libdns1605 - addressed in versions 9.16.6-150000.12.68.1, 9.16.6-150300.22.30.1
libdns1605-32bit-debuginfo - update to 9.16.6-150000.12.68.1
libdns1605-32bit - update to 9.16.6-150000.12.68.1
bind9.16 (Red Hat package) - addressed in versions 9.16.23-0.7.el8_6.2, 9.16.23-0.14.el8_8.1
bind9.16 - update to 9.16.23-0.14
bind9.16-chroot - update to 9.16.23-0.14
bind9.16-dnssec-utils - update to 9.16.23-0.14
bind9.16-libs - update to 9.16.23-0.14
bind9.16-utils - update to 9.16.23-0.14
bind9.16-doc - update to 9.16.23-0.14
bind9.16-license - update to 9.16.23-0.14
python3-bind9.16 - update to 9.16.23-0.14
bind-pkcs11-utils - update to 9.16.23-18
bind-dnssec-utils - update to 9.16.23-18
bind-dnssec-doc - update to 9.16.23-18
bind-license - update to 9.16.23-18
bind-pkcs11-libs - update to 9.16.23-18
bind - update to 9.16.42-1
bind9 (Debian package) - addressed in versions 1:9.16.42-1~deb11u1, 1:9.18.16-1~deb12u1
bind - addressed in versions 9.18.16-1.fc37, 9.18.16-1.fc38, 9.18.16-1.fc39
bind-dyndb-ldap - addressed in versions 11.10-15.fc37, 11.10-17.fc38, 11.10-17.fc39
EMC Cloud Tiering Appliance - addressed in versions 13.1.0.2.33, 13.2.0.2.24
IBM Robotic Process Automation - addressed in versions 21.0.7.8, 23.0.9
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Ubuntu update for bind9
- Debian update for bind9
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- Red Hat Enterprise Linux 9.0 Extended Update Support update for bind
- Red Hat Enterprise Linux 8.6 Extended Update Support update for bind9.16
- SUSE update for bind
- Red Hat Enterprise Linux 9 update for bind
- Red Hat Enterprise Linux 8 update for bind9.16
- Red Hat Enterprise Linux 8.6 Extended Update Support update for bind
- Red Hat Enterprise Linux 8 update for bind
- Ubuntu update for bind9
- Red Hat Enterprise Linux 7 update for bind
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for bind
- Amazon Linux AMI update for bind
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Red Hat Enterprise Linux 8 update for bind
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Virtualization 4.12
- VMware Tanzu products update for Bind
- CentOS 7 update for bind
- Resource exhaustion in IBM i
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh 2.4
- Multiple vulnerabiltiies in Red Hat OpenShift Service Mesh Containers 2.3
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.2
- Fedora 39 update for bind, bind-dyndb-ldap
- Fedora 38 update for bind, bind-dyndb-ldap
- Fedora 37 update for bind, bind-dyndb-ldap
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Oracle Solaris third-party software
- Multiple vulnerabilities in Migration Toolkit for Containers (MTC) 1.7
- Multiple vulnerabilities in Multicluster Engine for Kubernetes 2.1
- Resource exhaustion in IBM Integrated Analytics System
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Multiple vulnerabilities in Red Hat OpenShift Virtualization release 4.11
- Multiple vulnerabilities in Dell Data Protection Central
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Spectrum Conductor
- Multiple vulnerabilities in IBM QRadar SIEM
- VMware Tanzu update for Bind
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in Index Engines CyberSense
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Multiple vulnerabilities in IBM Operational Decision Manager
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM QRadar Network Packet Capture
- SUSE update for bind
- openEuler update for bind
- openEuler 22.03 LTS SP2 update for bind
- Multiple vulnerabilities in Dell EMC VxRail Appliance
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- Multiple vulnerabilities in Dell XtremIO X2
- Amazon Linux AMI update for bind
- Anolis OS update for bind
- Anolis OS update for bind9.16
- Anolis OS update for bind
- Multiple vulnerabilities in Dell EMC SRM and Dell EMC Storage Monitoring and Reporting (SMR)
- Juniper Session Smart Router update for third-party components