vulnerability

Red Hat: CVE-2023-50868: bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
2024-02-14
Added
2024-02-27
Modified
2025-03-21

Description

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

Solution(s)

redhat-upgrade-bindredhat-upgrade-bind-chrootredhat-upgrade-bind-debuginforedhat-upgrade-bind-debugsourceredhat-upgrade-bind-develredhat-upgrade-bind-dnssec-docredhat-upgrade-bind-dnssec-utilsredhat-upgrade-bind-dnssec-utils-debuginforedhat-upgrade-bind-docredhat-upgrade-bind-dyndb-ldapredhat-upgrade-bind-dyndb-ldap-debuginforedhat-upgrade-bind-dyndb-ldap-debugsourceredhat-upgrade-bind-export-develredhat-upgrade-bind-export-libsredhat-upgrade-bind-export-libs-debuginforedhat-upgrade-bind-libsredhat-upgrade-bind-libs-debuginforedhat-upgrade-bind-libs-literedhat-upgrade-bind-libs-lite-debuginforedhat-upgrade-bind-licenseredhat-upgrade-bind-lite-develredhat-upgrade-bind-pkcs11redhat-upgrade-bind-pkcs11-debuginforedhat-upgrade-bind-pkcs11-develredhat-upgrade-bind-pkcs11-libsredhat-upgrade-bind-pkcs11-libs-debuginforedhat-upgrade-bind-pkcs11-utilsredhat-upgrade-bind-pkcs11-utils-debuginforedhat-upgrade-bind-sdbredhat-upgrade-bind-sdb-chrootredhat-upgrade-bind-sdb-debuginforedhat-upgrade-bind-utilsredhat-upgrade-bind-utils-debuginforedhat-upgrade-bind9-16redhat-upgrade-bind9-16-chrootredhat-upgrade-bind9-16-debuginforedhat-upgrade-bind9-16-debugsourceredhat-upgrade-bind9-16-develredhat-upgrade-bind9-16-dnssec-utilsredhat-upgrade-bind9-16-dnssec-utils-debuginforedhat-upgrade-bind9-16-docredhat-upgrade-bind9-16-libsredhat-upgrade-bind9-16-libs-debuginforedhat-upgrade-bind9-16-licenseredhat-upgrade-bind9-16-utilsredhat-upgrade-bind9-16-utils-debuginforedhat-upgrade-dhclientredhat-upgrade-dhcpredhat-upgrade-dhcp-clientredhat-upgrade-dhcp-client-debuginforedhat-upgrade-dhcp-commonredhat-upgrade-dhcp-debuginforedhat-upgrade-dhcp-debugsourceredhat-upgrade-dhcp-develredhat-upgrade-dhcp-libsredhat-upgrade-dhcp-libs-debuginforedhat-upgrade-dhcp-relayredhat-upgrade-dhcp-relay-debuginforedhat-upgrade-dhcp-serverredhat-upgrade-dhcp-server-debuginforedhat-upgrade-dnsmasqredhat-upgrade-dnsmasq-debuginforedhat-upgrade-dnsmasq-debugsourceredhat-upgrade-dnsmasq-utilsredhat-upgrade-dnsmasq-utils-debuginforedhat-upgrade-python3-bindredhat-upgrade-python3-bind9-16redhat-upgrade-python3-unboundredhat-upgrade-python3-unbound-debuginforedhat-upgrade-unboundredhat-upgrade-unbound-debuginforedhat-upgrade-unbound-debugsourceredhat-upgrade-unbound-develredhat-upgrade-unbound-libsredhat-upgrade-unbound-libs-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.