CVE-2024-1975
EUVD-2024-1769223.07.2024, 15:15
If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| isc | bind | 9.0 ≤ 𝑥 ≤ 9.11.37 | ADP |
| isc | bind | 9.16.0 ≤ 𝑥 ≤ 9.16.50 | ADP |
| isc | bind | 9.16.8 ≤ 𝑥 ≤ 9.16.49-s1 | ADP |
| isc | bind | 9.18.0 ≤ 𝑥 ≤ 9.18.27 | ADP |
| isc | bind | 9.18.11 ≤ 𝑥 ≤ 9.18.27-s1 | ADP |
| isc | bind | 9.19.0 ≤ 𝑥 ≤ 9.19.24 | ADP |
| isc | bind | 9.9.3 ≤ 𝑥 ≤ 9.11.37-s1 | ADP |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| bind9 |
| ||||||||||||||||||
| isc-dhcp |
| ||||||||||||||||||
| bind9-libs |
|
References