Resource exhaustion in PowerDNS Recursor - CVE-2023-50868
Published: February 13, 2024 / Updated: August 23, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing DNSSEC related records. A remote attacker can trigger resource exhaustion by forcing the DNS server to query a specially crafted DNSSEC zone and perform a denial of service (DoS) attack.
Affected software
Unbound
ISC BIND
Debian Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Desktop 15 SP4
Gentoo Linux
Amazon Linux AMI
Oracle Linux
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Client Tools for SLE Micro
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Anolis OS
Red Hat Enterprise Linux Desktop
SUSE Enterprise Storage
IBM AIX
IBM i
OpenBSD
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
FreeBSD
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Package Hub 15
Basesystem Module
Server Applications Module
openSUSE Leap
openEuler
Oracle Solaris
Windows Server
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStore 9000X
SmartFabric Storage Software
LANTIME Operating System Firmware (LTOS)
BIG-IP
PowerStoreX OS
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
OpenShift Service Mesh
OpenShift Virtualization
IBM VIOS
RecoverPoint for Virtual Machines
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Dell EMC VxRail Appliance
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dnsmasq-base (Ubuntu package)
bind9 (Ubuntu package)
unbound
unbound-devel
unbound-libs
unbound-python
unbound (Red Hat package)
unbound (Ubuntu package)
libunbound8 (Ubuntu package)
unbound-debugsource
python3-unbound
unbound-debuginfo
unbound-help
unbound (Debian package)
unbound-utils
unbound-anchor
libuv1
libuv-devel
libuv-debugsource
libuv1-debuginfo
libunbound8-debuginfo
unbound-python-debuginfo
libunbound8
unbound-munin
unbound-anchor-debuginfo
libunbound-devel-mini-debugsource
libunbound-devel-mini-debuginfo
libunbound-devel-mini
bind-dyndb-ldap (Red Hat package)
dnsmasq (Red Hat package)
dnsmasq
dnsmasq-utils
net-dns/dnsmasq
dnsmasq-debugsource
dnsmasq-debuginfo
dnsmasq-utils-debuginfo
dhcp-common
dhclient
dhcp
dhcp-devel
dhcp-libs
dhcp (Red Hat package)
dhcp-client
dhcp-devel-doc
dhcp-relay
dhcp-server
pdns-recursor (Debian package)
pdns-recursor
bind (Red Hat package) main
bind
bind-pkcs11-libs
bind-pkcs11-devel
bind-devel
bind-chroot
bind-pkcs11
bind-lite-devel
bind-libs-lite
bind-libs
bind-export-libs
bind-export-devel
bind-license
bind-sdb
bind-sdb-chroot
bind-utils
bind-pkcs11-utils
bind-debugsource
bind-debuginfo
python3-bind
bind-utils-debuginfo
libisc1606
libbind9-1600
libisccc1600-debuginfo
libirs-devel
libns1604
libbind9-1600-debuginfo
libirs1601
libdns1605-debuginfo
bind-chrootenv
libdns1605
libirs1601-debuginfo
libns1604-debuginfo
libisccc1600
libisccfg1600
libbind9-1600-64bit
libdns1605-64bit
libisccfg1600-64bit
libisc1606-64bit
libirs1601-64bit
libisccc1600-64bit
bind-doc
libisccfg1600-debuginfo
libisc1606-debuginfo
bind9.16 (Red Hat package)
bind9.16-devel
bind9.16
bind9.16-chroot
bind9.16-libs
bind9.16-dnssec-utils
python3-bind9.16
bind9.16-license
bind9.16-doc
bind9.16-utils
bind-dnssec-utils
bind-dnssec-doc
bind9 (Debian package)
bind9-next
bind-dyndb-ldap
systemd
systemd-help
systemd-udev-compat
systemd-udev
systemd-libs
systemd-pam
systemd-debugsource
systemd-journal-remote
systemd-timesyncd
systemd-devel
systemd-container
systemd-networkd
systemd-nspawn
systemd-resolved
systemd-debuginfo
Oracle SD-WAN Edge
Ansible Automation Platform
APEX Cloud Platform for Red Hat OpenShift
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
Session Smart Router
Red Hat Migration Toolkit for Applications
IBM Security Verify Governance
Azure Stack
IBM Cloud Pak for Business Automation
IBM Observability with Instana
Juniper Junos Space
APEX Cloud Platform for Microsoft Azure
PowerProtect DP Series Appliance (IDPA)
Technical Support Appliance
PowerStore T
OpenManage Network Integration (OMNI)
IBM Cloud Pak for Watson AIOps
Storage Resource Manager
Storage Virtualize
EMC Cloud Tiering Appliance
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Dell EMC Storage Monitoring and Reporting (SMR)
How to mitigate CVE-2023-50868
Unbound - update to 1.19.1
SmartFabric Storage Software - update to 1.4.3
Migration Toolkit for Containers - update to 1.8.3
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.1, 2.5.2
Red Hat OpenShift Container Platform - addressed in versions 4.12.51, 4.12.53, 4.12.57, 4.13.42, 4.13.45, 4.14.32, 4.14.33, 4.15.10, 4.15.13
OpenShift Virtualization - addressed in versions 4.14.5, 4.14.6
RecoverPoint for Virtual Machines - update to 6.0 SP2 P1
LANTIME Operating System Firmware (LTOS) - update to 7.08.011
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - addressed in versions 7.6.8, 7.6.9
Dell EMC VxRail Appliance - update to 8.321
ISC BIND - addressed in versions 9.16.48, 9.16.48-S1, 9.18.24, 9.18.24-S1, 9.19.21
Juniper Junos Space - update to 24.1R2
dnsmasq-base (Ubuntu package) - addressed in versions Ubuntu Pro, 2.90-0ubuntu0.20.04.1, 2.90-0ubuntu0.22.04.1, 2.90-0ubuntu0.23.10.1
bind9 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:9.16.48-0ubuntu0.20.04.1, 1:9.18.18-0ubuntu0.22.04.2, 1:9.18.18-0ubuntu2.1
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
unbound - addressed in versions 1.6.6-5, 1.16.2-6, 1.17.1-6
unbound-devel - addressed in versions 1.6.6-5, 1.16.2-6, 1.17.1-6
unbound-libs - addressed in versions 1.6.6-5, 1.16.2-6, 1.17.1-6
unbound-python - update to 1.6.6-5
unbound (Red Hat package) - addressed in versions 1.6.6-5.el7_9.1, 1.7.3-12.el8_2.1, 1.7.3-15.el8_4.1, 1.7.3-17.el8_6.4, 1.13.1-13.el9_0.4, 1.16.2-3.el9_2.1, 1.16.2-3.el9_3.1, 1.16.2-5.el8_8.1, 1.16.2-5.el8_9.2
unbound (Ubuntu package) - addressed in versions 1.9.4-2ubuntu1.5, 1.13.1-1ubuntu5.4, 1.17.1-2ubuntu0.1
libunbound8 (Ubuntu package) - addressed in versions 1.9.4-2ubuntu1.5, 1.13.1-1ubuntu5.4, 1.17.1-2ubuntu0.1
Red Hat OpenShift GitOps - addressed in versions 1.10.5, 1.10.6, 1.11.4, 1.11.5, 1.12.2, 1.12.3, 1.12.4, 1.12.5, 1.13.1
unbound-debugsource - update to 1.11.0-11
unbound-libs - update to 1.11.0-11
python3-unbound - update to 1.11.0-11
unbound-debuginfo - update to 1.11.0-11
unbound-help - update to 1.11.0-11
unbound-devel - update to 1.11.0-11
unbound - update to 1.11.0-11
unbound (Debian package) - addressed in versions 1.13.1-1+deb11u2, 1.17.1-2+deb12u2
python3-unbound - addressed in versions 1.16.2-6, 1.17.1-6
unbound - update to 1.17.1-1
unbound-utils - update to 1.17.1-6
unbound-anchor - update to 1.17.1-6
libuv1 - update to 1.18.0-150000.3.2.1
libuv-devel - update to 1.18.0-150000.3.2.1
libuv-debugsource - update to 1.18.0-150000.3.2.1
libuv1-debuginfo - update to 1.18.0-150000.3.2.1
unbound - addressed in versions 1.19.1-1.fc38, 1.19.1-2.fc39, 1.19.1-3.fc39
libunbound8-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-python-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-anchor - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
libunbound8 - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-python - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-munin - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-anchor-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-debuginfo - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-debugsource - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
unbound-devel - addressed in versions 1.20.0-150100.10.13.1, 1.20.0-150600.23.3.1
libunbound-devel-mini-debugsource - update to 1.20.0-150600.23.3.1
libunbound-devel-mini-debuginfo - update to 1.20.0-150600.23.3.1
libunbound-devel-mini - update to 1.20.0-150600.23.3.1
bind-dyndb-ldap (Red Hat package) - addressed in versions 2.3-8.el6_10.1, 11.1-7.el7_9.1, 11.9-7.el9_0.1, 11.9-8.el9_2.2, 11.9-8.el9_3.3
Ansible Automation Platform - update to 2.4
PowerProtect DP Series Appliance (IDPA) - update to 2.7.7
dnsmasq (Red Hat package) - addressed in versions 2.79-11.el8_2.3, 2.79-15.el8_4.2, 2.79-21.el8_6.5, 2.79-26.el8_8.4, 2.79-31.el8_9.2, 2.85-3.el9_0.1, 2.85-6.el9_2.3, 2.85-14.el9_3.1
dnsmasq - update to 2.79-32.0.1
dnsmasq-utils - update to 2.79-32.0.1
net-dns/dnsmasq - update to 2.90
dnsmasq - update to 2.90
dnsmasq - update to 2.90-1
dnsmasq - addressed in versions 2.90-1.fc38, 2.90-1.fc39
dnsmasq-debugsource - addressed in versions 2.90-150100.7.28.1, 2.90-150400.16.3.1
dnsmasq-debuginfo - addressed in versions 2.90-150100.7.28.1, 2.90-150400.16.3.1
dnsmasq - addressed in versions 2.90-150100.7.28.1, 2.90-150400.16.3.1
dnsmasq-utils-debuginfo - update to 2.90-150400.16.3.1
dnsmasq-utils - update to 2.90-150400.16.3.1
Technical Support Appliance - update to 3.0.1
PowerStoreX OS - update to 3.2.1.5-2424458
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
PowerStore T - update to 3.6.1.4-2413340
OpenManage Network Integration (OMNI) - update to 3.7
dhcp-common - addressed in versions 4.2.5-83, 4.3.6-50.0.1
dhclient - update to 4.2.5-83
dhcp - update to 4.2.5-83
dhcp-devel - update to 4.2.5-83
dhcp-libs - addressed in versions 4.2.5-83, 4.3.6-50.0.1
dhcp (Red Hat package) - addressed in versions 4.2.5-83.el7_9.2, 4.3.6-40.el8_2.3, 4.3.6-44.el8_4.3, 4.3.6-47.el8_6.2, 4.3.6-49.el8_8.1, 4.3.6-49.el8_9.1, 4.3.6-50.el8_10
dhcp-client - update to 4.3.6-50.0.1
dhcp-devel-doc - update to 4.3.6-50.0.1
dhcp-relay - update to 4.3.6-50.0.1
dhcp-server - update to 4.3.6-50.0.1
IBM Cloud Pak for Watson AIOps - update to 4.6.0
pdns-recursor (Debian package) - update to 4.8.6-1
pdns-recursor - addressed in versions 4.8.6-1.el8, 4.8.6-1.el9, 4.8.6-1.fc38, 4.9.3-1.fc39
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 5.0.1.0
Storage Resource Manager - update to 5.0.1.0
Session Smart Router - addressed in versions 6.2.10, 6.3.7
Red Hat Migration Toolkit for Applications - update to 7.0.3
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF02
Storage Virtualize - addressed in versions 8.4.0.15, 8.5.0.13, 8.6.0.5, 8.7.0.0
IBM Integrated Analytics System - update to 8.8.24.10.SP1
bind (Red Hat package) main - addressed in versions 9.8.2-0.68.rc1.el6_10.14, 9.11.4-26.P2.el7_9.16, 9.11.13-6.el8_2.7, 9.11.26-4.el8_4.4, 9.11.36-3.el8_6.7, 9.11.36-8.el8_8.4, 9.11.36-11.el8_9.1, 9.11.36-14.el8_10, 9.16.23-1.el9_0.5, 9.16.23-11.el9_2.4, 9.16.23-14.el9_3.4, 9.16.23-18.el9_4.1
bind - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-14.0.1
bind-devel - addressed in versions 9.11.21-21, 9.16.23-23
bind-export-devel - update to 9.11.21-21
bind-export-libs - update to 9.11.21-21
bind-libs - addressed in versions 9.11.21-21, 9.16.23-23
bind-libs-lite - update to 9.11.21-21
bind-pkcs11 - addressed in versions 9.11.21-21, 9.16.23-23
bind-debugsource - addressed in versions 9.11.21-21, 9.16.23-23
bind-debuginfo - addressed in versions 9.11.21-21, 9.16.23-23
bind-chroot - addressed in versions 9.11.21-21, 9.16.23-23
bind-pkcs11-devel - addressed in versions 9.11.21-21, 9.16.23-23
bind - addressed in versions 9.11.21-21, 9.16.23-23
bind-utils - addressed in versions 9.11.21-21, 9.16.23-23
python3-bind - addressed in versions 9.11.21-21, 9.16.23-23
python3-bind - update to 9.11.36-14.0.1
bind-utils-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libisc1606 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libirs-devel - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libns1604 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libirs1601 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-devel - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-chrootenv - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-debugsource - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libdns1605 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libisccc1600 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libbind9-1600-64bit - update to 9.16.6-150000.12.74.2
libdns1605-64bit - update to 9.16.6-150000.12.74.2
libisccfg1600-64bit - update to 9.16.6-150000.12.74.2
libisc1606-64bit - update to 9.16.6-150000.12.74.2
libirs1601-64bit - update to 9.16.6-150000.12.74.2
libisccc1600-64bit - update to 9.16.6-150000.12.74.2
bind-doc - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
python3-bind - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1
bind-utils - addressed in versions 9.16.6-150000.12.74.2, 9.16.6-150300.22.44.1, 9.16.48-150400.5.40.1, 9.16.48-150500.8.16.1
bind9.16 (Red Hat package) - addressed in versions 9.16.23-0.7.el8_6.5, 9.16.23-0.14.el8_8.4, 9.16.23-0.16.el8_9.2
bind9.16-devel - update to 9.16.23-0.14
bind9.16 - update to 9.16.23-0.14
bind9.16-chroot - update to 9.16.23-0.14
bind9.16-libs - update to 9.16.23-0.14
bind9.16-dnssec-utils - update to 9.16.23-0.14
python3-bind9.16 - update to 9.16.23-0.14
bind9.16-license - update to 9.16.23-0.14
bind9.16-doc - update to 9.16.23-0.14
bind9.16-utils - update to 9.16.23-0.14
bind-dnssec-utils - update to 9.16.23-23
bind-pkcs11-libs - update to 9.16.23-23
bind-pkcs11-utils - update to 9.16.23-23
bind-dnssec-doc - update to 9.16.23-23
bind-license - update to 9.16.23-23
bind9 (Debian package) - addressed in versions 1:9.16.48-1, 1:9.18.24-1
bind - update to 9.16.48-1
bind - addressed in versions 9.18.24-1.fc38, 9.18.24-1.fc39, 9.18.24-1.fc41
bind9-next - addressed in versions 9.19.21-1.fc38, 9.19.21-1.fc39
IBM Security Verify Governance - update to 10.0.2.0.4
Azure Stack - update to 10.2402
bind-dyndb-ldap - update to 11.1-7
Oracle Solaris - addressed in versions 11.3 ESU 36.33, 11.4 SRU 68
bind-dyndb-ldap - addressed in versions 11.10-23.fc38, 11.10-24.fc39, 11.10-27.fc41
EMC Cloud Tiering Appliance - update to 13.2.0.2.31
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1
systemd - update to 243-78
systemd-help - update to 243-78
systemd-udev-compat - update to 243-78
systemd-udev - update to 243-78
systemd-libs - update to 243-78
systemd-pam - update to 243-78
systemd-debugsource - update to 243-78
systemd-journal-remote - update to 243-78
systemd-timesyncd - update to 243-78
systemd-devel - update to 243-78
systemd-container - update to 243-78
systemd-networkd - update to 243-78
systemd-nspawn - update to 243-78
systemd-resolved - update to 243-78
systemd-debuginfo - update to 243-78
IBM Observability with Instana - update to 272
Windows Server - addressed in versions 2008 R2 6.1.7601.27170, 2012 R2 6.3.9600.22023, 2012 6.2.9200.24919, 2016 10.0.14393.7070, 2019 10.0.17763.5936, 2022 10.0.20348.2522, 2022 10.0.20348.2527
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Remote denial of service in PowerDNS Recursor
- Ubuntu update for bind9
- Multiple vulnerabilities in ISC BIND
- Fedora 38 update for dnsmasq
- Fedora 39 update for dnsmasq
- Fedora 38 update for unbound
- Slackware Linux update for dnsmasq
- Fedora 38 update for pdns-recursor
- Fedora 39 update for pdns-recursor
- Fedora EPEL 9 update for pdns-recursor
- Fedora EPEL 8 update for pdns-recursor
- Fedora 39 update for unbound
- Multiple vulnerabilities in Unbound
- Fedora 39 update for unbound
- Fedora 39 update for bind9-next
- Fedora 38 update for bind9-next
- Fedora 41 update for bind, bind-dyndb-ldap
- Fedora 39 update for bind, bind-dyndb-ldap
- Fedora 38 update for bind, bind-dyndb-ldap
- SUSE update for bind
- SUSE update for bind
- Ubuntu update for bind9
- Red Hat Enterprise Linux 9 update for unbound
- Red Hat Enterprise Linux 9.2 Extended Update Support update for unbound
- Red Hat Enterprise Linux 8.8 Extended Update Support update for unbound
- Ubuntu update for dnsmasq
- Ubuntu update for unbound
- Red Hat Enterprise Linux 8 update for unbound
- Multiple vulnerabilities in IBM i
- Red Hat Enterprise Linux 9 update for dnsmasq
- Red Hat Enterprise Linux 8 update for dnsmasq
- OpenBSD update for Bind
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- openEuler update for unbound
- Red Hat Enterprise Linux 9.2 Extended Update Support update for dnsmasq
- Red Hat Enterprise Linux 9.0 Extended Update Support update for dnsmasq
- Red Hat Enterprise Linux 8.8 Extended Update Support update for dnsmasq
- Red Hat Enterprise Linux 8.6 Extended Update Support update for dnsmasq
- FreeBSD update for unbound
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Red Hat Enterprise Linux 8.6 Extended Update Support update for bind9.16
- Red Hat Enterprise Linux 8.8 Extended Update Support update for bind9.16
- Ubuntu update for bind9
- Red Hat Enterprise Linux 8 update for bind9.16
- Red Hat Enterprise Linux 8 update for bind and dhcp
- Red Hat Enterprise Linux 9 update for bind
- Red Hat Enterprise Linux 9.0 Extended Update Support update for unbound
- Red Hat Enterprise Linux 8.6 Extended Update Support update for unbound
- Red Hat Enterprise Linux 9 update for bind
- Red Hat Enterprise Linux 9.2 update for bind
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers (MTC) 1.8
- Multiple vulnerabilities in Red Hat OpenShift Service Mesh Containers 2.5
- Ubuntu update for dnsmasq
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- openEuler update for systemd
- Red Hat Enterprise Linux 8 update for unbound
- Red Hat Enterprise Linux 9 update for bind
- Multiple vulnerabilities in IBM QRadar SIEM
- SUSE update for unbound
- Multiple vulnerabilities in IBM AIX and IBM VIOS
- Red Hat Enterprise Linux 8 update for unbound
- Red Hat Enterprise Linux 8.6 Extended Update Support update for bind and dhcp
- Red Hat Enterprise Linux 8.8 Extended Update Support update for bind and dhcp
- Red Hat Enterprise Linux 8 update for bind and dhcp
- Red Hat Enterprise Linux 8.2 Advanced Update Support update for bind
- Red Hat Enterprise Linux 8 update for bind and dhcp
- SUSE update for bind
- SUSE update for unbound
- Denial of service in Microsoft Windows Server
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Red Hat Enterprise Linux 8 update for dnsmasq
- Multiple vulnerabilities in Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software
- Red Hat Enterprise Linux 8.2 Advanced Update Support update for dnsmasq
- SUSE update for bind
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Red Hat Enterprise Linux 7 update for bind, bind-dyndb-ldap, and dhcp
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Juniper Secure Analytics (JSA)
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in IBM Observability with Instana
- Debian update for unbound
- Debian update for bind9
- Debian update for pdns-recursor
- Resource exhaustion in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.13
- Multiple vulnerabilities in Dell Storage Resource Manager (SRM) and Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Amazon Linux AMI update for unbound
- Amazon Linux AMI update for dnsmasq
- Amazon Linux AMI update for bind
- Multiple vulnerabilities in IBM Watson Assistant for IBM Cloud Pak for Data
- openEuler 22.03 LTS SP3 update for bind
- openEuler 22.03 LTS SP1 update for bind
- Denial of service in F5 BIG-IP DNSSEC support
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in IBM Storage Virtualize
- Multiple vulnerabilities in IBM Security Verify Governance - Identity Manager
- IBM Integrated Analytics System update for BIND
- Multiple vulnerabilities in IBM Technical Support Appliance
- Gentoo update for Dnsmasq
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for unbound
- Multiple vulnerabilities in Dell PowerStore T
- Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION update for bind and bind-dyndb-ldap
- Multiple vulnerabilities in Junos Space
- SUSE update for dnsmasq
- SUSE update for dnsmasq
- Multiple vulnerabilities in Dell OpenManage Network Integration (OMNI)
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Multiple vulnerabilities in Dell PowerProtect DP Series Appliance (IDPA)
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Anolis OS update for unbound
- Anolis OS update for bind and dhcp
- Anolis OS update for bind9.16
- Anolis OS update for dnsmasq
- Anolis OS update for multiple packages
- Anolis OS update for unbound
- Dell SmartFabric Storage Software update for third-party components
- Dell VxRail Appliance 8.x update for third-party components
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in Meinberg LANTIME firmware (July 2024)
- Dell RecoverPoint for Virtual Machines update for third-party components
- Multiple vulnerabilities in Dell PowerStore X
- Anolis OS update for unbound
- openEuler 20.03 LTS SP4 update for bind
- Juniper Session Smart Router update for third-party components
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat Migration Toolkit for Applications 7.0
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.10
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.11