Rapid7
BACK TO VEDB

CVE-2023-6516: Allocation of Resources Without Limits or Throttling

REQUEST DEMO

To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.

CVSS Details

  • CVSS 3.1 Base Score: 7.5
  • CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Covered by Rapid7

ProductVendor AdvisorySolution FileAddedPublished
Alma_linux
View advisory ↗View advisory ↗View advisory ↗View advisory ↗
alma-upgrade-bindalma-upgrade-bind-chrootalma-upgrade-bind-develalma-upgrade-bind-dnssec-docalma-upgrade-bind-dnssec-utilsalma-upgrade-bind-docalma-upgrade-bind-dyndb-ldapalma-upgrade-bind-libsalma-upgrade-bind-licensealma-upgrade-bind-utilsalma-upgrade-bind9.16alma-upgrade-bind9.16-chrootalma-upgrade-bind9.16-develalma-upgrade-bind9.16-dnssec-utilsalma-upgrade-bind9.16-docalma-upgrade-bind9.16-libsalma-upgrade-bind9.16-licensealma-upgrade-bind9.16-utilsalma-upgrade-python3-bindalma-upgrade-python3-bind9.16
Apr 15, 2024Feb 13, 2024
Alpine Linux
View advisory ↗View advisory ↗
alpine-linux-upgrade-bind
Mar 26, 2024Feb 13, 2024
Amazon_linux_2023
View advisory ↗
amazon-linux-2023-upgrade-bindamazon-linux-2023-upgrade-bind-chrootamazon-linux-2023-upgrade-bind-debuginfoamazon-linux-2023-upgrade-bind-debugsourceamazon-linux-2023-upgrade-bind-develamazon-linux-2023-upgrade-bind-dlz-filesystemamazon-linux-2023-upgrade-bind-dlz-filesystem-debuginfoamazon-linux-2023-upgrade-bind-dlz-ldapamazon-linux-2023-upgrade-bind-dlz-ldap-debuginfoamazon-linux-2023-upgrade-bind-dlz-mysqlamazon-linux-2023-upgrade-bind-dlz-mysql-debuginfoamazon-linux-2023-upgrade-bind-dlz-sqlite3amazon-linux-2023-upgrade-bind-dlz-sqlite3-debuginfoamazon-linux-2023-upgrade-bind-dnssec-docamazon-linux-2023-upgrade-bind-dnssec-utilsamazon-linux-2023-upgrade-bind-dnssec-utils-debuginfoamazon-linux-2023-upgrade-bind-docamazon-linux-2023-upgrade-bind-libsamazon-linux-2023-upgrade-bind-libs-debuginfoamazon-linux-2023-upgrade-bind-licenseamazon-linux-2023-upgrade-bind-pkcs11amazon-linux-2023-upgrade-bind-pkcs11-debuginfoamazon-linux-2023-upgrade-bind-pkcs11-develamazon-linux-2023-upgrade-bind-pkcs11-libsamazon-linux-2023-upgrade-bind-pkcs11-libs-debuginfoamazon-linux-2023-upgrade-bind-pkcs11-utilsamazon-linux-2023-upgrade-bind-pkcs11-utils-debuginfoamazon-linux-2023-upgrade-bind-utilsamazon-linux-2023-upgrade-bind-utils-debuginfoamazon-linux-2023-upgrade-python3-bind
Feb 17, 2025Feb 13, 2024
Debian
View advisory ↗
debian-upgrade-bind9
Jul 30, 2024Feb 13, 2024
Dell Powerstore Dsa2024462
View advisory ↗View advisory ↗
dell-powerstoreos-upgrade-latest
Oct 23, 2025Nov 20, 2024
Dell Powerstore Dsa2024497
View advisory ↗View advisory ↗
dell-powerstoreos-upgrade-latest
Oct 23, 2025Dec 19, 2024
Dell Powerstore Dsa2025050
View advisory ↗View advisory ↗
dell-powerstoreos-upgrade-latest
Oct 23, 2025Jan 28, 2025
Dns Bind
View advisory ↗View advisory ↗
upgrade-isc-bind-latest
Feb 15, 2024Feb 15, 2024
Huawei Euleros 2_0_sp11
View advisory ↗
huawei-euleros-2_0_sp11-upgrade-bindhuawei-euleros-2_0_sp11-upgrade-bind-chroothuawei-euleros-2_0_sp11-upgrade-bind-dnssec-dochuawei-euleros-2_0_sp11-upgrade-bind-dnssec-utilshuawei-euleros-2_0_sp11-upgrade-bind-libshuawei-euleros-2_0_sp11-upgrade-bind-licensehuawei-euleros-2_0_sp11-upgrade-bind-pkcs11huawei-euleros-2_0_sp11-upgrade-bind-pkcs11-libshuawei-euleros-2_0_sp11-upgrade-bind-pkcs11-utilshuawei-euleros-2_0_sp11-upgrade-bind-utilshuawei-euleros-2_0_sp11-upgrade-python3-bind
Jun 3, 2024Feb 13, 2024
Huawei Euleros 2_0_sp12
View advisory ↗
huawei-euleros-2_0_sp12-upgrade-bindhuawei-euleros-2_0_sp12-upgrade-bind-chroothuawei-euleros-2_0_sp12-upgrade-bind-dnssec-dochuawei-euleros-2_0_sp12-upgrade-bind-dnssec-utilshuawei-euleros-2_0_sp12-upgrade-bind-libshuawei-euleros-2_0_sp12-upgrade-bind-licensehuawei-euleros-2_0_sp12-upgrade-bind-pkcs11huawei-euleros-2_0_sp12-upgrade-bind-pkcs11-libshuawei-euleros-2_0_sp12-upgrade-bind-pkcs11-utilshuawei-euleros-2_0_sp12-upgrade-bind-utilshuawei-euleros-2_0_sp12-upgrade-python3-bind
May 31, 2024Feb 13, 2024
Ibm Aix
View advisory ↗View advisory ↗
ibm-aix-bind_advisory26
Jun 5, 2024Feb 13, 2024
Oracle_linux—
oracle-linux-upgrade-bindoracle-linux-upgrade-bind9-16oracle-linux-upgrade-bind9-16-chrootoracle-linux-upgrade-bind9-16-develoracle-linux-upgrade-bind9-16-dnssec-utilsoracle-linux-upgrade-bind9-16-docoracle-linux-upgrade-bind9-16-libsoracle-linux-upgrade-bind9-16-licenseoracle-linux-upgrade-bind9-16-utilsoracle-linux-upgrade-bind-chrootoracle-linux-upgrade-bind-develoracle-linux-upgrade-bind-dnssec-docoracle-linux-upgrade-bind-dnssec-utilsoracle-linux-upgrade-bind-docoracle-linux-upgrade-bind-dyndb-ldaporacle-linux-upgrade-bind-libsoracle-linux-upgrade-bind-licenseoracle-linux-upgrade-bind-utilsoracle-linux-upgrade-python3-bindoracle-linux-upgrade-python3-bind9-16
Apr 12, 2024Feb 13, 2024
Redhat_linux
View advisory ↗
redhat-upgrade-bindredhat-upgrade-bind-chrootredhat-upgrade-bind-debuginforedhat-upgrade-bind-debugsourceredhat-upgrade-bind-develredhat-upgrade-bind-dnssec-docredhat-upgrade-bind-dnssec-utilsredhat-upgrade-bind-dnssec-utils-debuginforedhat-upgrade-bind-docredhat-upgrade-bind-dyndb-ldapredhat-upgrade-bind-dyndb-ldap-debuginforedhat-upgrade-bind-dyndb-ldap-debugsourceredhat-upgrade-bind-libsredhat-upgrade-bind-libs-debuginforedhat-upgrade-bind-licenseredhat-upgrade-bind-utilsredhat-upgrade-bind-utils-debuginforedhat-upgrade-bind9-16redhat-upgrade-bind9-16-chrootredhat-upgrade-bind9-16-debuginforedhat-upgrade-bind9-16-debugsourceredhat-upgrade-bind9-16-develredhat-upgrade-bind9-16-dnssec-utilsredhat-upgrade-bind9-16-dnssec-utils-debuginforedhat-upgrade-bind9-16-docredhat-upgrade-bind9-16-libsredhat-upgrade-bind9-16-libs-debuginforedhat-upgrade-bind9-16-licenseredhat-upgrade-bind9-16-utilsredhat-upgrade-bind9-16-utils-debuginforedhat-upgrade-python3-bindredhat-upgrade-python3-bind9-16
Apr 3, 2024Feb 13, 2024
Rocky_linux
View advisory ↗View advisory ↗View advisory ↗
rocky-upgrade-bindrocky-upgrade-bind-chrootrocky-upgrade-bind-debuginforocky-upgrade-bind-debugsourcerocky-upgrade-bind-develrocky-upgrade-bind-dnssec-utilsrocky-upgrade-bind-dnssec-utils-debuginforocky-upgrade-bind-dyndb-ldaprocky-upgrade-bind-dyndb-ldap-debuginforocky-upgrade-bind-dyndb-ldap-debugsourcerocky-upgrade-bind-libsrocky-upgrade-bind-libs-debuginforocky-upgrade-bind-utilsrocky-upgrade-bind-utils-debuginforocky-upgrade-bind9.16rocky-upgrade-bind9.16-chrootrocky-upgrade-bind9.16-debuginforocky-upgrade-bind9.16-debugsourcerocky-upgrade-bind9.16-develrocky-upgrade-bind9.16-dnssec-utilsrocky-upgrade-bind9.16-dnssec-utils-debuginforocky-upgrade-bind9.16-libsrocky-upgrade-bind9.16-libs-debuginforocky-upgrade-bind9.16-utilsrocky-upgrade-bind9.16-utils-debuginfo
May 8, 2024Feb 13, 2024
Suse—
suse-upgrade-bindsuse-upgrade-bind-chrootenvsuse-upgrade-bind-develsuse-upgrade-bind-docsuse-upgrade-bind-utilssuse-upgrade-libbind9-1600suse-upgrade-libdns1605suse-upgrade-libirs-develsuse-upgrade-libirs1601suse-upgrade-libisc1606suse-upgrade-libisccc1600suse-upgrade-libisccfg1600suse-upgrade-libns1604suse-upgrade-libuv-develsuse-upgrade-libuv1suse-upgrade-python3-bind
Feb 22, 2024Feb 13, 2024
Ubuntu
View advisory ↗
ubuntu-upgrade-bind9
Feb 21, 2024Feb 13, 2024
Vmware Photon_os
View advisory ↗
vmware-photon_os_update_tdnf
Jan 20, 2025Feb 13, 2024

Prioritise with Active Threat Intelligence

With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.

Explore Intelligence Hub

CVE details

CVSS v4 ScoreN/A
CVSS v3 Score7.5 High
EPSS Score1%
EPSS Percentile62%
In CISA KEV CatalogueFalse

Published

Feb 13, 2024

References

  • NVD ↗
    Rapid7
    Request Demo
    • Request Demo
    • Explore platform
    • Exposure Management
    • Attack Surface Management
    • Vulnerability Management
    • Cloud-Native Application Protection
    • Application Security
    • Next-Gen SIEM
    • Threat Intelligence Platform
    • Start a Free Trial
    • AI-Engine
    • Rapid7 Labs
    • Self-Guided Platform Tour
    • Talk to an Expert
    • Rapid7 Threat Intelligence
    • All Products
    • Managed Detection and Response
    • MDR for Microsoft
    • MDR for Enterprise
    • Incident Response Services
    • Rapid7 vs. Them
    • Customer Stories
    • MDR Product Tour
    • MDR ROI Calculator
    • Managed Vulnerability Management
    • Continuous Red Teaming
    • Managed Application Security
    • Penetration Testing Services
    • All services
    • READ NOW
    • Rapid7 Labs
    • Emergent Threat Response
    • Vulnerability & Exploit Database
    • Blog
    • Webinars and Events
    • Resource Library
    • Cybersecurity Fundamentals
    • Product Documentation
    • Product Release Notes
    • Product Extensions
    • Product Toolkits
    • Customer Support
    • Rapid7 Forum
    • Partnerships Overview
    • PACT Partner Program
    • PACT for Service Providers
    • Partner Directory
    • Technology Partners
    • AWS Partnership
    • Partner Login
    • Become a Partner
    • Become a partner
    • About Us
    • Leadership Team
    • Our Customers
    • Careers
    • Contact Us
    • Newsroom
    • Awards and Recognition
    • Investors
    • Social Good
    • Culture
    • Boston Bruins Partnership
    • Book live demo
    Rapid7

    Get Started

    Command Platform
    Exposure Management
    MDR Services
    Solutions

    Take Action

    Start a Free Trial
    Take a Product Tour
    Get Breach Support
    Contact Sales

    Company

    • About Us
    • Leadership
    • Newsroom
    • Our Customers
    • Partner Programs
    • Investors
    • Careers

    Stay Informed

    • Blog
    • Emergent Threat Response
    • Webinars & Events
    • Rapid7 Labs Research
    • Vulnerability Database
    • Security Fundamentals

    For Customers

    • Sign In
    • Support Portal
    • Product Documentation
    • Extension Library
    • Rapid7 Academy
    • Customer Escalation Portal

    Contact Support

    • +1-866-390-8113

    Follow Us

    LinkedIn icon
    LinkedIn
    X (Twitter) icon
    X (Twitter)
    Facebook icon
    Facebook
    Instagram icon
    Instagram
    Bluesky icon
    Bluesky
    © Rapid7
    Legal TermsPrivacy PolicyExport NoticeTrustCookie ListAccessibility Statement