Resource exhaustion in ISC BIND - CVE-2023-4236

 

Resource exhaustion in ISC BIND - CVE-2023-4236

Published: September 20, 2023


Vulnerability identifier: #VU80930
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-4236
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling DNS-over-TLS queries. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

ISC BIND
Debian Linux
Ubuntu
Fedora
Isolation Segment
VMware Tanzu Application Service for VMs
Redis for Pivotal Platform
VMware Tanzu Operations Manager
bind9 (Ubuntu package)
bind9 (Debian package)
bind
bind-dyndb-ldap

How to mitigate CVE-2023-4236

Install updates from vendor's website.

ISC BIND - addressed in versions 9.18.19, 9.18.19-S1
VMware Tanzu Operations Manager - update to 3.0.17
bind9 (Ubuntu package) - addressed in versions 1:9.16.1-0ubuntu2.16, 1:9.18.12-0ubuntu0.22.04.3, 1:9.18.12-1ubuntu1.2
bind9 (Debian package) - addressed in versions 1:9.16.44-1~deb11u1, 1:9.18.19-1~deb12u1
bind - addressed in versions 9.18.19-1.fc37, 9.18.19-1.fc38, 9.18.19-1.fc39, 9.18.19-1.fc40
bind-dyndb-ldap - addressed in versions 11.10-17.fc37, 11.10-21.fc38, 11.10-21.fc39, 11.10-21.fc40

External References

Related Security Bulletins