Resource exhaustion in PowerDNS Recursor - CVE-2023-50387
Published: February 13, 2024 / Updated: May 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing DNSSEC related records. A remote attacker can trigger resource exhaustion by forcing the DNS server to query a specially crafted DNSSEC zone and perform a denial of service (DoS) attack.
Affected software
Unbound
ISC BIND
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Desktop 15 SP4
Debian Linux
Oracle Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux Server
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
SUSE Enterprise Storage
IBM AIX
OpenBSD
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Fedora
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
FreeBSD
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Server Applications Module
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Windows Server
Oracle Solaris
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
BIG-IP
PowerStoreX OS
Data Lakehouse
Ansible Automation Platform
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
Red Hat Migration Toolkit for Applications
IBM Security Verify Governance
Azure Stack
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Service Mesh
OpenShift Virtualization
IBM VIOS
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Dell EMC VxRail Appliance
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dnsmasq-base (Ubuntu package)
bind9 (Ubuntu package)
unbound
unbound-python
unbound-libs
unbound-devel
unbound (Red Hat package)
libunbound8 (Ubuntu package)
unbound (Ubuntu package)
unbound-debuginfo
unbound-help
unbound-debugsource
python3-unbound
unbound (Debian package)
unbound-utils
unbound-anchor
libuv1
libuv-devel
libuv-debugsource
libuv1-debuginfo
unbound-python-debuginfo
unbound-anchor-debuginfo
libunbound8
unbound-munin
libunbound8-debuginfo
libunbound-devel-mini-debugsource
libunbound-devel-mini-debuginfo
libunbound-devel-mini
bind-dyndb-ldap (Red Hat package)
dnsmasq (Red Hat package)
dnsmasq-utils
dnsmasq
net-dns/dnsmasq
dnsmasq-debugsource
dnsmasq-debuginfo
dnsmasq-utils-debuginfo
dhcp-common
dhcp-libs
dhcp-devel
dhcp
dhclient
dhcp (Red Hat package)
dhcp-relay
dhcp-devel-doc
dhcp-server
dhcp-client
pdns-recursor (Debian package)
pdns-recursor
bind (Red Hat package) main
bind-libs
bind-utils
bind-export-libs
bind-license
bind-export-devel
bind-sdb-chroot
bind-sdb
bind-chroot
bind-pkcs11-utils
bind-devel
bind-pkcs11-libs
bind-pkcs11-devel
bind-pkcs11
bind-lite-devel
bind-libs-lite
bind
bind-debuginfo
python3-bind
bind-debugsource
libisccc1600-debuginfo
libirs1601
libdns1605
bind-chrootenv
bind-utils-debuginfo
libbind9-1600-debuginfo
libns1604
libirs-devel
libisccfg1600-64bit
libisc1606-debuginfo
bind-doc
libisccc1600-64bit
libbind9-1600-64bit
libirs1601-64bit
libisc1606-64bit
libdns1605-64bit
libns1604-debuginfo
libirs1601-debuginfo
libbind9-1600
libdns1605-debuginfo
libisc1606
libisccfg1600-debuginfo
libisccfg1600
libisccc1600
bind9.16 (Red Hat package)
python3-bind9.16
bind9.16
bind9.16-chroot
bind9.16-devel
bind9.16-dnssec-utils
bind9.16-libs
bind9.16-utils
bind9.16-license
bind9.16-doc
bind-dnssec-utils
bind-dnssec-doc
bind9 (Debian package)
bind9-next
bind-dyndb-ldap
systemd-udev
systemd
systemd-debuginfo
systemd-resolved
systemd-nspawn
systemd-networkd
systemd-libs
systemd-container
systemd-timesyncd
systemd-journal-remote
systemd-debugsource
systemd-pam
systemd-help
systemd-udev-compat
systemd-devel
systemd-rpm-macros
systemd-oomd-defaults
systemd-doc
systemd-tests
systemd-storagetm
systemd-standalone-shutdown
systemd-standalone-tmpfiles
systemd-standalone-sysusers
systemd-standalone-repart
systemd-pcrlock
systemd-bsod
systemd-boot-unsigned
systemd-battery-check
Juniper Junos Space
APEX Cloud Platform for Microsoft Azure
Technical Support Appliance
PowerStore T
OpenManage Network Integration (OMNI)
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
Storage Virtualize
EMC Cloud Tiering Appliance
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2023-50387
Data Lakehouse - update to 1.1.0.0
Unbound - update to 1.19.1
SmartFabric Storage Software - update to 1.4.3
Migration Toolkit for Containers - update to 1.8.3
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.1, 2.5.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.51, 4.12.53, 4.12.57, 4.13.42, 4.13.45, 4.14.32, 4.14.33, 4.15.10, 4.15.13
OpenShift Virtualization - addressed in versions 4.14.5, 4.14.6
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
LANTIME Operating System Firmware (LTOS) - update to 7.08.011
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - addressed in versions 7.6.8, 7.6.9
Dell EMC VxRail Appliance - update to 8.321
ISC BIND - addressed in versions 9.16.48, 9.16.48-S1, 9.18.24, 9.18.24-S1, 9.19.21
BIG-IP - addressed in versions 16.1.5, 17.1.1.1
Juniper Junos Space - update to 24.1R2
dnsmasq-base (Ubuntu package) - addressed in versions Ubuntu Pro, 2.90-0ubuntu0.20.04.1, 2.90-0ubuntu0.22.04.1, 2.90-0ubuntu0.23.10.1
bind9 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:9.16.48-0ubuntu0.20.04.1, 1:9.18.18-0ubuntu0.22.04.2, 1:9.18.18-0ubuntu2.1
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
unbound - addressed in versions 1.6.6-5, 1.16.2-6, 1.17.1-6
unbound-python - update to 1.6.6-5
unbound-libs - addressed in versions 1.6.6-5, 1.16.2-6, 1.17.1-6
unbound-devel - addressed in versions 1.6.6-5, 1.16.2-6, 1.17.1-6
unbound (Red Hat package) - addressed in versions 1.6.6-5.el7_9.1, 1.7.3-12.el8_2.1, 1.7.3-15.el8_4.1, 1.7.3-17.el8_6.4, 1.13.1-13.el9_0.4, 1.16.2-3.el9_2.1, 1.16.2-3.el9_3.1, 1.16.2-5.el8_8.1, 1.16.2-5.el8_9.2
libunbound8 (Ubuntu package) - addressed in versions 1.9.4-2ubuntu1.5, 1.13.1-1ubuntu5.4, 1.17.1-2ubuntu0.1
unbound (Ubuntu package) - addressed in versions 1.9.4-2ubuntu1.5, 1.13.1-1ubuntu5.4, 1.17.1-2ubuntu0.1
Red Hat OpenShift GitOps - addressed in versions 1.10.5, 1.10.6, 1.11.4, 1.11.5, 1.12.2, 1.12.3, 1.12.4, 1.12.5, 1.13.1
unbound - update to 1.11.0-11
unbound-debuginfo - update to 1.11.0-11
unbound-devel - update to 1.11.0-11
unbound-help - update to 1.11.0-11
unbound-debugsource - update to 1.11.0-11
unbound-libs - update to 1.11.0-11
python3-unbound - update to 1.11.0-11
unbound (Debian package) - addressed in versions 1.13.1-1+deb11u2, 1.17.1-2+deb12u2
python3-unbound - addressed in versions 1.16.2-6, 1.17.1-6
unbound - update to 1.17.1-1
unbound-utils - update to 1.17.1-6
unbound-anchor - update to 1.17.1-6
libuv1 - update to 1.18.0-150000.3.2.1
libuv-devel - update to 1.18.0-150000.3.2.1
libuv-debugsource - update to 1.18.0-150000.3.2.1
libuv1-debuginfo - update to 1.18.0-150000.3.2.1
unbound - addressed in versions 1.19.1-1.fc38, 1.19.1-2.fc39, 1.19.1-3.fc39
unbound-python-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-anchor-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
libunbound8 - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-devel - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-debugsource - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-munin - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-python - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-anchor - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
libunbound8-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
libunbound-devel-mini-debugsource - update to 1.20.0-150600.23.3.1
libunbound-devel-mini-debuginfo - update to 1.20.0-150600.23.3.1
libunbound-devel-mini - update to 1.20.0-150600.23.3.1
bind-dyndb-ldap (Red Hat package) - addressed in versions 2.3-8.el6_10.1, 11.1-7.el7_9.1, 11.9-7.el9_0.1, 11.9-8.el9_2.2, 11.9-8.el9_3.3
Ansible Automation Platform - update to 2.4
dnsmasq (Red Hat package) - addressed in versions 2.79-11.el8_2.3, 2.79-15.el8_4.2, 2.79-21.el8_6.5, 2.79-26.el8_8.4, 2.79-31.el8_9.2, 2.85-3.el9_0.1, 2.85-6.el9_2.3, 2.85-14.el9_3.1
dnsmasq-utils - update to 2.79-32.0.1
dnsmasq - update to 2.79-32.0.1
net-dns/dnsmasq - update to 2.90
dnsmasq - update to 2.90
dnsmasq - update to 2.90-1
dnsmasq - addressed in versions 2.90-1.fc38, 2.90-1.fc39
dnsmasq-debugsource - addressed in versions 2.90-150100.7.28.1, 2.90-150400.16.3.1
dnsmasq - addressed in versions 2.90-150100.7.28.1, 2.90-150400.16.3.1
dnsmasq-debuginfo - addressed in versions 2.90-150100.7.28.1, 2.90-150400.16.3.1
dnsmasq-utils-debuginfo - update to 2.90-150400.16.3.1
dnsmasq-utils - update to 2.90-150400.16.3.1
Technical Support Appliance - update to 3.0.1
PowerStoreX OS - update to 3.2.1.5-2424458
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
PowerStore T - update to 3.6.1.4-2413340
OpenManage Network Integration (OMNI) - update to 3.7
dhcp-common - addressed in versions 4.2.5-83, 4.3.6-50.0.1
dhcp-libs - addressed in versions 4.2.5-83, 4.3.6-50.0.1
dhcp-devel - update to 4.2.5-83
dhcp - update to 4.2.5-83
dhclient - update to 4.2.5-83
dhcp (Red Hat package) - addressed in versions 4.2.5-83.el7_9.2, 4.3.6-40.el8_2.3, 4.3.6-44.el8_4.3, 4.3.6-47.el8_6.2, 4.3.6-49.el8_8.1, 4.3.6-49.el8_9.1, 4.3.6-50.el8_10
dhcp-relay - update to 4.3.6-50.0.1
dhcp-devel-doc - update to 4.3.6-50.0.1
dhcp-server - update to 4.3.6-50.0.1
dhcp-client - update to 4.3.6-50.0.1
IBM Cloud Pak for Watson AIOps - update to 4.6.0
pdns-recursor (Debian package) - update to 4.8.6-1
pdns-recursor - addressed in versions 4.8.6-1.el8, 4.8.6-1.el9, 4.8.6-1.fc38, 4.9.3-1.fc39
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0
Storage Resource Manager - update to 5.0.1.0
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Red Hat Migration Toolkit for Applications - update to 7.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF02
Storage Virtualize - addressed in versions 8.4.0.15, 8.5.0.13, 8.6.0.5, 8.7.0.0
IBM Integrated Analytics System - update to 8.8.24.10.SP1
bind (Red Hat package) main - addressed in versions 9.8.2-0.68.rc1.el6_10.14, 9.11.4-26.P2.el7_9.16, 9.11.13-6.el8_2.7, 9.11.26-4.el8_4.4, 9.11.36-3.el8_6.7, 9.11.36-8.el8_8.4, 9.11.36-11.el8_9.1, 9.11.36-14.el8_10, 9.16.23-1.el9_0.5, 9.16.23-11.el9_2.4, 9.16.23-14.el9_3.4, 9.16.23-18.el9_4.1
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-debuginfo - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
python3-bind - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind-utils - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind-pkcs11-devel - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind-chroot - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind-debugsource - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind-devel - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind-export-devel - update to 9.11.21-21
bind-export-libs - update to 9.11.21-21
bind-libs - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
bind-libs-lite - update to 9.11.21-21
bind-pkcs11 - addressed in versions 9.11.21-21, 9.16.23-21, 9.16.23-22
python3-bind - update to 9.11.36-14.0.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libirs1601 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libdns1605 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-debugsource - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
bind-chrootenv - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-devel - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-utils-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libns1604 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libirs-devel - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libisccfg1600-64bit - update to 9.16.6-150000.12.74.2
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
python3-bind - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
bind-doc - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libisccc1600-64bit - update to 9.16.6-150000.12.74.2
libbind9-1600-64bit - update to 9.16.6-150000.12.74.2
libirs1601-64bit - update to 9.16.6-150000.12.74.2
libisc1606-64bit - update to 9.16.6-150000.12.74.2
libdns1605-64bit - update to 9.16.6-150000.12.74.2
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-utils - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libisc1606 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libisccc1600 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind9.16 (Red Hat package) - addressed in versions 9.16.23-0.7.el8_6.5, 9.16.23-0.14.el8_8.4, 9.16.23-0.16.el8_9.2
python3-bind9.16 - update to 9.16.23-0.14
bind9.16 - update to 9.16.23-0.14
bind9.16-chroot - update to 9.16.23-0.14
bind9.16-devel - update to 9.16.23-0.14
bind9.16-dnssec-utils - update to 9.16.23-0.14
bind9.16-libs - update to 9.16.23-0.14
bind9.16-utils - update to 9.16.23-0.14
bind9.16-license - update to 9.16.23-0.14
bind9.16-doc - update to 9.16.23-0.14
bind-license - addressed in versions 9.16.23-21, 9.16.23-22
bind-pkcs11-libs - addressed in versions 9.16.23-21, 9.16.23-22
bind-dnssec-utils - addressed in versions 9.16.23-21, 9.16.23-22
bind-dnssec-doc - addressed in versions 9.16.23-21, 9.16.23-22
bind-pkcs11-utils - addressed in versions 9.16.23-21, 9.16.23-22
bind - update to 9.16.48
bind - update to 9.16.48-1
bind9 (Debian package) - addressed in versions 1:9.16.48-1, 1:9.18.24-1
bind - addressed in versions 9.18.24-1.fc38, 9.18.24-1.fc39, 9.18.24-1.fc41
bind9-next - addressed in versions 9.19.21-1.fc38, 9.19.21-1.fc39
IBM Security Verify Governance - update to 10.0.2.0.4
Azure Stack - update to 10.2402
bind-dyndb-ldap - update to 11.1-7
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68
bind-dyndb-ldap - addressed in versions 11.10-23.fc38, 11.10-24.fc39, 11.10-27.fc41
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
systemd-udev - update to 243-78
systemd - update to 243-78
systemd-debuginfo - update to 243-78
systemd-resolved - update to 243-78
systemd-nspawn - update to 243-78
systemd-networkd - update to 243-78
systemd-libs - update to 243-78
systemd-container - update to 243-78
systemd-timesyncd - update to 243-78
systemd-journal-remote - update to 243-78
systemd-debugsource - update to 243-78
systemd-pam - update to 243-78
systemd-help - update to 243-78
systemd-udev-compat - update to 243-78
systemd-devel - update to 243-78
systemd-rpm-macros - update to 255-10
systemd-oomd-defaults - update to 255-10
systemd-doc - update to 255-10
systemd-udev - update to 255-10
systemd-tests - update to 255-10
systemd-storagetm - update to 255-10
systemd-standalone-shutdown - update to 255-10
systemd-standalone-tmpfiles - update to 255-10
systemd-standalone-sysusers - update to 255-10
systemd-standalone-repart - update to 255-10
systemd-resolved - update to 255-10
systemd-pcrlock - update to 255-10
systemd-pam - update to 255-10
systemd-libs - update to 255-10
systemd-journal-remote - update to 255-10
systemd-devel - update to 255-10
systemd-container - update to 255-10
systemd-bsod - update to 255-10
systemd-boot-unsigned - update to 255-10
systemd-battery-check - update to 255-10
systemd - update to 255-10
IBM Observability with Instana - update to 272
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote denial of service in PowerDNS Recursor
- Ubuntu update for bind9
- Multiple vulnerabilities in ISC BIND
- Slackware Linux update for bind
- Denial of service in Microsoft Windows Server
- Fedora 38 update for dnsmasq
- Fedora 39 update for dnsmasq
- Fedora 38 update for unbound
- Slackware Linux update for dnsmasq
- Fedora 38 update for pdns-recursor
- Fedora 39 update for pdns-recursor
- Fedora EPEL 9 update for pdns-recursor
- Fedora EPEL 8 update for pdns-recursor
- Fedora 39 update for unbound
- Multiple vulnerabilities in Unbound
- Fedora 39 update for unbound
- Fedora 39 update for bind9-next
- Fedora 38 update for bind9-next
- Fedora 41 update for bind, bind-dyndb-ldap
- Fedora 39 update for bind, bind-dyndb-ldap
- Fedora 38 update for bind, bind-dyndb-ldap
- SUSE update for bind
- SUSE update for bind
- Ubuntu update for bind9
- Red Hat Enterprise Linux 9 update for unbound
- Red Hat Enterprise Linux 9.2 Extended Update Support update for unbound
- Red Hat Enterprise Linux 8.8 Extended Update Support update for unbound
- Ubuntu update for dnsmasq
- Ubuntu update for unbound
- Red Hat Enterprise Linux 8 update for unbound
- Red Hat Enterprise Linux 9 update for dnsmasq
- Red Hat Enterprise Linux 8 update for dnsmasq
- OpenBSD update for Bind
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- openEuler 22.03 LTS update for bind
- openEuler 22.03 LTS SP1 update for bind
- openEuler 22.03 LTS SP2 update for bind
- openEuler 22.03 LTS SP3 update for bind
- openEuler update for unbound
- Red Hat Enterprise Linux 9.2 Extended Update Support update for dnsmasq
- Red Hat Enterprise Linux 9.0 Extended Update Support update for dnsmasq
- Red Hat Enterprise Linux 8.8 Extended Update Support update for dnsmasq
- Red Hat Enterprise Linux 8.6 Extended Update Support update for dnsmasq
- FreeBSD update for unbound
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 8.6 Extended Update Support update for bind9.16
- Red Hat Enterprise Linux 8.8 Extended Update Support update for bind9.16
- Ubuntu update for bind9
- Red Hat Enterprise Linux 8 update for bind9.16
- Red Hat Enterprise Linux 8 update for bind and dhcp
- Red Hat Enterprise Linux 9 update for bind
- Red Hat Enterprise Linux 9.0 Extended Update Support update for unbound
- Red Hat Enterprise Linux 8.6 Extended Update Support update for unbound
- Red Hat Enterprise Linux 9 update for bind
- Red Hat Enterprise Linux 9.2 update for bind
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- Ubuntu update for dnsmasq
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- openEuler update for systemd
- Red Hat Enterprise Linux 8 update for unbound
- Red Hat Enterprise Linux 9 update for bind
- Multiple vulnerabilities in IBM QRadar SIEM
- SUSE update for unbound
- Multiple vulnerabilities in IBM AIX and IBM VIOS
- Red Hat Enterprise Linux 8 update for unbound
- Red Hat Enterprise Linux 8.6 Extended Update Support update for bind and dhcp
- Red Hat Enterprise Linux 8.8 Extended Update Support update for bind and dhcp
- Red Hat Enterprise Linux 8 update for bind and dhcp
- Red Hat Enterprise Linux 8.2 Advanced Update Support update for bind
- Red Hat Enterprise Linux 8 update for bind and dhcp
- Red Hat Enterprise Linux 8 update for the idm:DL1 and idm:client modules
- SUSE update for bind
- SUSE update for unbound
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Red Hat Enterprise Linux 8 update for dnsmasq
- Multiple vulnerabilities in Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software
- Red Hat Enterprise Linux 8.2 Advanced Update Support update for dnsmasq
- SUSE update for bind
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Red Hat Enterprise Linux 7 update for bind, bind-dyndb-ldap, and dhcp
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in IBM Observability with Instana
- Debian update for unbound
- Debian update for bind9
- Debian update for pdns-recursor
- Resource exhaustion in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Amazon Linux AMI update for unbound
- Amazon Linux AMI update for dnsmasq
- Amazon Linux AMI update for bind
- Denial of service in F5 BIG-IP DNSSEC implementation
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in IBM Storage Virtualize
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- IBM Integrated Analytics System update for BIND
- Multiple vulnerabilities in IBM Technical Support Appliance
- Gentoo update for Dnsmasq
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for unbound
- Multiple vulnerabilities in Dell PowerStore T
- Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION update for bind and bind-dyndb-ldap
- Multiple vulnerabilities in Junos Space
- SUSE update for dnsmasq
- SUSE update for dnsmasq
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Anolis OS update for unbound
- Anolis OS update for bind and dhcp
- Anolis OS update for bind9.16
- Anolis OS update for dnsmasq
- Anolis OS update for multiple packages
- Anolis OS update for unbound
- Dell SmartFabric Storage Software update for third-party components
- Dell VxRail Appliance 8.x update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in Meinberg LANTIME firmware (July 2024)
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in Dell PowerStore X
- Anolis OS update for unbound
- openEuler 20.03 LTS SP4 update for bind
- Anolis OS update for systemd
- Juniper Session Smart Router update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11