Resource exhaustion in ISC BIND - CVE-2023-3341

 

Resource exhaustion in ISC BIND - CVE-2023-3341

Published: September 20, 2023


Vulnerability identifier: #VU80931
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-3341
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling control channel messages . A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

ISC BIND
Amazon Linux AMI
Oracle Linux
Debian Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Manager Server
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
CentOS
Anolis OS
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Power, big endian
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Fedora
IBM AIX
Isolation Segment
VMware Tanzu Application Service for VMs
Service Telemetry Framework
OpenShift Pipelines
Migration Toolkit for Virtualization
Ansible Automation Platform
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Spectrum Conductor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
Session Smart Router
IBM Spectrum Symphony
Redis for Pivotal Platform
Node Health Check Operator
Self Node Remediation Operator
Multicluster Engine for Kubernetes
OpenShift Service Mesh
OpenShift Virtualization
VMware Tanzu Operations Manager
OpenShift Data Foundation (formerly OpenShift Container Storage)
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Dell EMC PowerProtect Data Protection
IBM Cloud Pak for Watson AIOps
SmartFabric OS10
Robotic Process Automation for Cloud Pak
ObjectScale
Storage Defender – Data Protect
Enterprise SONiC
XtremIO X2
Index Engines CyberSense
Dell PowerProtect Cyber Recovery
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Dell EMC NetWorker vProxy
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bind9 (Ubuntu package)
libbind9-160 (Ubuntu package)
libbind9-140 (Ubuntu package)
libbind9-90 (Ubuntu package)
bind-dyndb-ldap (Red Hat package)
bind (Red Hat package) main
bind
bind-pkcs11-devel
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind-utils
bind-license
bind-libs
bind-chroot
bind-devel
bind-export-devel
bind-pkcs11
bind-export-libs
bind-lite-devel
bind-libs-lite
python3-bind
bind-debugsource
bind-debuginfo
libisccfg163-debuginfo
libisc1107-debuginfo-32bit
libisc1107-32bit
python-bind
bind-doc
libbind9-161
libisccc161
libisc1107-debuginfo
libdns1110-debuginfo
liblwres161-debuginfo
liblwres161
bind-utils-debuginfo
libisc1107
libdns1110
libisccfg163
bind-chrootenv
libbind9-161-debuginfo
libisccc161-debuginfo
libirs161
libirs161-debuginfo
libisccc1600
libbind9-1600
libirs1601
libdns1605
libisc1606-64bit
libbind9-1600-64bit
libisccfg1600-64bit
libirs1601-64bit
libdns1605-64bit
libisccc1600-64bit
libns1604
libisccfg1600
libirs-devel
libisc1606
libisccfg1600-32bit-debuginfo
libisccc1600-32bit-debuginfo
libirs1601-32bit
libbind9-1600-32bit-debuginfo
libisc1606-32bit
libns1604-32bit-debuginfo
libirs1601-32bit-debuginfo
libisccfg1600-32bit
libns1604-32bit
libisccc1600-32bit
libdns1605-32bit
libdns1605-32bit-debuginfo
bind-devel-32bit
libisc1606-32bit-debuginfo
libbind9-1600-32bit
libdns1605-debuginfo
libbind9-1600-debuginfo
libirs1601-debuginfo
libns1604-debuginfo
libisccc1600-debuginfo
libisccfg1600-debuginfo
libisc1606-debuginfo
bind9.16 (Red Hat package)
bind9.16-devel
python3-bind9.16
bind9.16-license
bind9.16-doc
bind9.16-utils
bind9.16-libs
bind9.16-chroot
bind9.16
bind9.16-dnssec-utils
bind9 (Debian package)
bind-dyndb-ldap
IBM VIOS
RecoverPoint for VMs
IBM Integrated Analytics System
Dell EMC VxRail Appliance

How to mitigate CVE-2023-3341

Install updates from vendor's website.

ISC BIND - addressed in versions 9.16.44, 9.16.44-S1, 9.18.19, 9.18.19-S1, 9.19.17
Isolation Segment - addressed in versions 3.0.19, 4.0.11
VMware Tanzu Application Service for VMs - addressed in versions 3.0.19, 4.0.11
Node Health Check Operator - addressed in versions 0.4.1, 0.6.1
Self Node Remediation Operator - update to 0.5.1
Service Telemetry Framework - update to 1.5.2
Migration Toolkit for Containers - addressed in versions 1.7.14, 1.8.1
OpenShift Pipelines - addressed in versions 1.10.6, 1.11.2, 1.12.1
Multicluster Engine for Kubernetes - addressed in versions 2.1.9, 2.2.9, 2.3.3
OpenShift Service Mesh - addressed in versions 2.2.11, 2.3.8, 2.4.4
Migration Toolkit for Virtualization - addressed in versions 2.4.3, 2.5.2
Dell EMC PowerProtect Data Protection - update to 2.7.8
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.7, 4.0.5, 4.1.4, 4.2.2
Red Hat OpenShift Container Platform - addressed in versions 4.11.52, 4.12.39, 4.13.17, 4.14.0
OpenShift Virtualization - addressed in versions 4.11.7, 4.12.8, 4.13.5
OpenShift Logging - update to 5.5.17
Red Hat Migration Toolkit for Applications - update to 6.1.4
IBM Qradar SIEM - update to 7.5.0 Update Pack 7 IF02
Juniper Secure Analytics (JSA) - addressed in versions 7.5.0 UP7 IF02, 7.5.0 UP8 IF03
SmartFabric OS10 - addressed in versions 10.5.5.9, 10.5.6.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.11, 23.0.12
bind9 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:9.16.1-0ubuntu2.16, 1:9.18.12-0ubuntu0.22.04.3, 1:9.18.12-1ubuntu1.2
libbind9-160 (Ubuntu package) - update to Ubuntu Pro
libbind9-140 (Ubuntu package) - update to Ubuntu Pro
libbind9-90 (Ubuntu package) - update to Ubuntu Pro
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 2.0
bind-dyndb-ldap (Red Hat package) - update to 2.3-8.el6_10.1
IBM Spectrum Conductor - update to 2.5.1 Fix 601861
VMware Tanzu Operations Manager - addressed in versions 2.10.65, 3.0.17
IBM VIOS - update to 3.1.4.40
Enterprise SONiC - update to 4.2.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
Dell Secure Connect Gateway - update to 5.20.00.10
RecoverPoint for VMs - update to 6.0.SP1.P1
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
XtremIO X2 - update to 6.4.2-13
IBM AIX - update to 7.2.5 SP08
IBM Spectrum Symphony - update to 7.3.2 Fix 601860
IBM Integrated Analytics System - update to 7.9.23.12.SP23
Dell EMC VxRail Appliance - update to 8.0.120
Index Engines CyberSense - update to 8.4
bind (Red Hat package) main - addressed in versions 9.8.2-0.68.rc1.el6_10.14, 9.11.4-26.P2.el7_9.15, 9.11.4-26.P2.el8_1.8, 9.11.13-6.el8_2.6, 9.11.26-4.el8_4.3, 9.11.36-3.el8_6.5, 9.11.36-8.el8_8.2, 9.16.23-1.el9_0.3, 9.16.23-11.el9_2.2
bind - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-8
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-8
python3-bind - update to 9.11.21-18
bind - update to 9.11.21-18
bind-debugsource - update to 9.11.21-18
bind-export-devel - update to 9.11.21-18
bind-libs - update to 9.11.21-18
bind-utils - update to 9.11.21-18
bind-pkcs11 - update to 9.11.21-18
bind-export-libs - update to 9.11.21-18
bind-devel - update to 9.11.21-18
bind-chroot - update to 9.11.21-18
bind-debuginfo - update to 9.11.21-18
bind-pkcs11-devel - update to 9.11.21-18
bind-libs-lite - update to 9.11.21-18
libisccfg163-debuginfo - update to 9.11.22-3.49.1
bind-debuginfo - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1, 9.16.44-150400.5.37.2, 9.16.44-150500.8.12.2
bind-debugsource - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1, 9.16.44-150400.5.37.2, 9.16.44-150500.8.12.2
libisc1107-debuginfo-32bit - update to 9.11.22-3.49.1
libisc1107-32bit - update to 9.11.22-3.49.1
python-bind - update to 9.11.22-3.49.1
bind-doc - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1, 9.16.44-150400.5.37.2, 9.16.44-150500.8.12.2
libbind9-161 - update to 9.11.22-3.49.1
libisccc161 - update to 9.11.22-3.49.1
libisc1107-debuginfo - update to 9.11.22-3.49.1
libdns1110-debuginfo - update to 9.11.22-3.49.1
bind-utils - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1, 9.16.44-150400.5.37.2, 9.16.44-150500.8.12.2
liblwres161-debuginfo - update to 9.11.22-3.49.1
liblwres161 - update to 9.11.22-3.49.1
bind-utils-debuginfo - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1, 9.16.44-150400.5.37.2, 9.16.44-150500.8.12.2
libisc1107 - update to 9.11.22-3.49.1
libdns1110 - update to 9.11.22-3.49.1
libisccfg163 - update to 9.11.22-3.49.1
bind-chrootenv - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libbind9-161-debuginfo - update to 9.11.22-3.49.1
libisccc161-debuginfo - update to 9.11.22-3.49.1
libirs161 - update to 9.11.22-3.49.1
libirs161-debuginfo - update to 9.11.22-3.49.1
bind - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1, 9.16.44-150400.5.37.2, 9.16.44-150500.8.12.2
bind-devel - addressed in versions 9.11.22-3.49.1, 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
python3-bind - update to 9.11.36-8
libisccc1600 - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libirs1601 - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libdns1605 - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libisc1606-64bit - update to 9.16.6-150000.12.71.1
libbind9-1600-64bit - update to 9.16.6-150000.12.71.1
libisccfg1600-64bit - update to 9.16.6-150000.12.71.1
libirs1601-64bit - update to 9.16.6-150000.12.71.1
libdns1605-64bit - update to 9.16.6-150000.12.71.1
libisccc1600-64bit - update to 9.16.6-150000.12.71.1
python3-bind - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1, 9.16.44-150400.5.37.2, 9.16.44-150500.8.12.2
libns1604 - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libirs-devel - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libisc1606 - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libisccfg1600-32bit-debuginfo - update to 9.16.6-150000.12.71.1
libisccc1600-32bit-debuginfo - update to 9.16.6-150000.12.71.1
libirs1601-32bit - update to 9.16.6-150000.12.71.1
libbind9-1600-32bit-debuginfo - update to 9.16.6-150000.12.71.1
libisc1606-32bit - update to 9.16.6-150000.12.71.1
libns1604-32bit-debuginfo - update to 9.16.6-150000.12.71.1
libirs1601-32bit-debuginfo - update to 9.16.6-150000.12.71.1
libisccfg1600-32bit - update to 9.16.6-150000.12.71.1
libns1604-32bit - update to 9.16.6-150000.12.71.1
libisccc1600-32bit - update to 9.16.6-150000.12.71.1
libdns1605-32bit - update to 9.16.6-150000.12.71.1
libdns1605-32bit-debuginfo - update to 9.16.6-150000.12.71.1
bind-devel-32bit - update to 9.16.6-150000.12.71.1
libisc1606-32bit-debuginfo - update to 9.16.6-150000.12.71.1
libbind9-1600-32bit - update to 9.16.6-150000.12.71.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.71.1, 9.16.6-150300.22.41.1
bind9.16 (Red Hat package) - addressed in versions 9.16.23-0.7.el8_6.3, 9.16.23-0.14.el8_8.2
bind9.16-devel - update to 9.16.23-0.14
python3-bind9.16 - update to 9.16.23-0.14
bind9.16-license - update to 9.16.23-0.14
bind9.16-doc - update to 9.16.23-0.14
bind9.16-utils - update to 9.16.23-0.14
bind9.16-libs - update to 9.16.23-0.14
bind9.16-chroot - update to 9.16.23-0.14
bind9.16 - update to 9.16.23-0.14
bind9.16-dnssec-utils - update to 9.16.23-0.14
bind - update to 9.16.42-1
bind - update to 9.16.44
bind9 (Debian package) - addressed in versions 1:9.16.44-1~deb11u1, 1:9.18.19-1~deb12u1
bind - addressed in versions 9.18.19-1.fc37, 9.18.19-1.fc38, 9.18.19-1.fc39, 9.18.19-1.fc40
bind-dyndb-ldap - addressed in versions 11.10-17.fc37, 11.10-21.fc38, 11.10-21.fc39, 11.10-21.fc40
Dell EMC NetWorker vProxy - addressed in versions 19.9.0.4, 19.10
Dell PowerProtect Cyber Recovery - update to 19.15.0.1

External References

Related Security Bulletins