CVE-2024-12705
EUVD-2024-5106229.01.2025, 22:15
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bind9 |
| ||||||||||||||||||
| isc-dhcp |
| ||||||||||||||||||
| bind9-libs |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| bind |
| ||||||||
| bind-doc |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| bind9.18 |
| ||
| bind9.18-chroot |
| ||
| bind9.18-devel |
| ||
| bind9.18-dnssec-utils |
| ||
| bind9.18-doc |
| ||
| bind9.18-libs |
| ||
| bind9.18-utils |
|