vulnerability
Red Hat: CVE-2023-50868: bind9: Preparing an NSEC3 closest encloser proof can exhaust CPU resources (Multiple Advisories)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | 2024-02-14 | 2024-02-27 | 2025-03-21 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
2024-02-14
Added
2024-02-27
Modified
2025-03-21
Description
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Solution(s)
redhat-upgrade-bindredhat-upgrade-bind-chrootredhat-upgrade-bind-debuginforedhat-upgrade-bind-debugsourceredhat-upgrade-bind-develredhat-upgrade-bind-dnssec-docredhat-upgrade-bind-dnssec-utilsredhat-upgrade-bind-dnssec-utils-debuginforedhat-upgrade-bind-docredhat-upgrade-bind-dyndb-ldapredhat-upgrade-bind-dyndb-ldap-debuginforedhat-upgrade-bind-dyndb-ldap-debugsourceredhat-upgrade-bind-export-develredhat-upgrade-bind-export-libsredhat-upgrade-bind-export-libs-debuginforedhat-upgrade-bind-libsredhat-upgrade-bind-libs-debuginforedhat-upgrade-bind-libs-literedhat-upgrade-bind-libs-lite-debuginforedhat-upgrade-bind-licenseredhat-upgrade-bind-lite-develredhat-upgrade-bind-pkcs11redhat-upgrade-bind-pkcs11-debuginforedhat-upgrade-bind-pkcs11-develredhat-upgrade-bind-pkcs11-libsredhat-upgrade-bind-pkcs11-libs-debuginforedhat-upgrade-bind-pkcs11-utilsredhat-upgrade-bind-pkcs11-utils-debuginforedhat-upgrade-bind-sdbredhat-upgrade-bind-sdb-chrootredhat-upgrade-bind-sdb-debuginforedhat-upgrade-bind-utilsredhat-upgrade-bind-utils-debuginforedhat-upgrade-bind9-16redhat-upgrade-bind9-16-chrootredhat-upgrade-bind9-16-debuginforedhat-upgrade-bind9-16-debugsourceredhat-upgrade-bind9-16-develredhat-upgrade-bind9-16-dnssec-utilsredhat-upgrade-bind9-16-dnssec-utils-debuginforedhat-upgrade-bind9-16-docredhat-upgrade-bind9-16-libsredhat-upgrade-bind9-16-libs-debuginforedhat-upgrade-bind9-16-licenseredhat-upgrade-bind9-16-utilsredhat-upgrade-bind9-16-utils-debuginforedhat-upgrade-dhclientredhat-upgrade-dhcpredhat-upgrade-dhcp-clientredhat-upgrade-dhcp-client-debuginforedhat-upgrade-dhcp-commonredhat-upgrade-dhcp-debuginforedhat-upgrade-dhcp-debugsourceredhat-upgrade-dhcp-develredhat-upgrade-dhcp-libsredhat-upgrade-dhcp-libs-debuginforedhat-upgrade-dhcp-relayredhat-upgrade-dhcp-relay-debuginforedhat-upgrade-dhcp-serverredhat-upgrade-dhcp-server-debuginforedhat-upgrade-dnsmasqredhat-upgrade-dnsmasq-debuginforedhat-upgrade-dnsmasq-debugsourceredhat-upgrade-dnsmasq-utilsredhat-upgrade-dnsmasq-utils-debuginforedhat-upgrade-python3-bindredhat-upgrade-python3-bind9-16redhat-upgrade-python3-unboundredhat-upgrade-python3-unbound-debuginforedhat-upgrade-unboundredhat-upgrade-unbound-debuginforedhat-upgrade-unbound-debugsourceredhat-upgrade-unbound-develredhat-upgrade-unbound-libsredhat-upgrade-unbound-libs-debuginfo
References
- NVD-CVE-2023-50868
- REDHAT-RHSA-2024:0965
- REDHAT-RHSA-2024:0977
- REDHAT-RHSA-2024:0981
- REDHAT-RHSA-2024:0982
- REDHAT-RHSA-2024:1334
- REDHAT-RHSA-2024:1335
- REDHAT-RHSA-2024:1522
- REDHAT-RHSA-2024:1543
- REDHAT-RHSA-2024:1544
- REDHAT-RHSA-2024:1545
- REDHAT-RHSA-2024:1647
- REDHAT-RHSA-2024:1648
- REDHAT-RHSA-2024:1781
- REDHAT-RHSA-2024:1782
- REDHAT-RHSA-2024:1789
- REDHAT-RHSA-2024:1800
- REDHAT-RHSA-2024:1801
- REDHAT-RHSA-2024:1803
- REDHAT-RHSA-2024:1804
- REDHAT-RHSA-2024:2551
- REDHAT-RHSA-2024:2720
- REDHAT-RHSA-2024:2721
- REDHAT-RHSA-2024:3271
- REDHAT-RHSA-2024:3741

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.