CVE-2023-2828
Summary
| CVE | CVE-2023-2828 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-06-21 17:15:00 UTC |
| Updated | 2023-07-21 19:19:00 UTC |
| Description | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit.
It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded.
This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 15144 ISC BIND Denial of Service (DoS) Vulnerability
- 160787 Oracle Enterprise Linux Security Update for bind (ELSA-2023-4099)
- 160793 Oracle Enterprise Linux Security Update for bind9.16 (ELSA-2023-4100)
- 160801 Oracle Enterprise Linux Security Update for bind (ELSA-2023-4102)
- 160802 Oracle Enterprise Linux Security Update for bind (ELSA-2023-4152)
- 199435 Ubuntu Security Notification for Bind Vulnerabilities (USN-6183-1)
- 199537 Ubuntu Security Notification for Bind Vulnerability (USN-6183-2)
- 241780 Red Hat Update for bind (RHSA-2023:4005)
- 241789 Red Hat Update for bind9.16 (RHSA-2023:4037)
- 241814 Red Hat Update for bind9.16 (RHSA-2023:4100)
- 241815 Red Hat Update for bind (RHSA-2023:4102)
- 241817 Red Hat Update for bind (RHSA-2023:4101)
- 241818 Red Hat Update for bind (RHSA-2023:4099)
- 241819 Red Hat Update for bind (RHSA-2023:4153)
- 241827 Red Hat Update for bind (RHSA-2023:4154)
- 241834 Red Hat Update for bind (RHSA-2023:4152)
- 241868 Red Hat Update for bind (RHSA-2023:4332)
- 257247 CentOS Security Update for bind (CESA-2023:4152)
- 284044 Fedora Security Update for bind (FEDORA-2023-8e1ddb1fa2)
- 284045 Fedora Security Update for bind (FEDORA-2023-c0ff5a2f68)
- 284113 Fedora Security Update for bind (FEDORA-2023-1d526d551c)
- 330148 IBM AIX Denial of Service (DoS) ISC BIND Vulnerability (bind_advisory24)
- 355584 Amazon Linux Security Advisory for bind : ALAS2-2023-2112
- 355628 Amazon Linux Security Advisory for bind : ALAS2023-2023-240
- 355679 Amazon Linux Security Advisory for bind : ALAS-2023-1789
- 378748 Alibaba Cloud Linux Security Update for bind (ALINUX3-SA-2023:0083)
- 6000038 Debian Security Update for bind9 (DLA 3498-1)
- 6000172 Debian Security Update for bind9 (DSA 5439-1)
- 673275 EulerOS Security Update for bind (EulerOS-SA-2023-2602)
- 673278 EulerOS Security Update for bind (EulerOS-SA-2023-2572)
- 673415 EulerOS Security Update for bind (EulerOS-SA-2023-3113)
- 673477 EulerOS Security Update for bind (EulerOS-SA-2023-2778)
- 673576 EulerOS Security Update for dhcp (EulerOS-SA-2023-3204)
- 673690 EulerOS Security Update for bind (EulerOS-SA-2023-2802)
- 673814 EulerOS Security Update for dhcp (EulerOS-SA-2023-3327)
- 673862 EulerOS Security Update for dhcp (EulerOS-SA-2023-3169)
- 673912 EulerOS Security Update for bind (EulerOS-SA-2023-2837)
- 673993 EulerOS Security Update for bind (EulerOS-SA-2023-2854)
- 674100 EulerOS Security Update for dhcp (EulerOS-SA-2023-3295)
- 754158 SUSE Enterprise Linux Security Update for bind (SUSE-SU-2023:2794-1)
- 754159 SUSE Enterprise Linux Security Update for bind (SUSE-SU-2023:2793-1)
- 755853 SUSE Enterprise Linux Security Update for bind (SUSE-SU-2023:2954-1)
- 907141 Common Base Linux Mariner (CBL-Mariner) Security Update for bind (27209-1)
- 907177 Common Base Linux Mariner (CBL-Mariner) Security Update for bind (27238-1)
- 941182 AlmaLinux Security Update for bind9.16 (ALSA-2023:4100)
- 941183 AlmaLinux Security Update for bind (ALSA-2023:4102)
- 941184 AlmaLinux Security Update for bind (ALSA-2023:4099)
- 960960 Rocky Linux Security Update for bind9.16 (RLSA-2023:4100)
- 960965 Rocky Linux Security Update for bind (RLSA-2023:4102)
- 960972 Rocky Linux Security Update for bind (RLSA-2023:4099)