Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 11 DSA-5504-1 Critical: Bind9 DoS Vulnerabilities Fixed

debian
Calendar Grey September 22, 2023
Debian Logo
Critical bind9 patch released addressing multiple security flaws. Upgrading recommended to avoid potential issues and ensure system reliability.
Several vulnerabilities were discovered in BIND, a DNS server implementation

Summary

CVE-2023-3341

A stack exhaustion flaw was discovered in the control channel code
which may result in denial of service (named daemon crash).

CVE-2023-4236

Robert Story discovered that a flaw in the networking code handling
DNS-over-TLS queries could cause named to terminate unexpectedly due
to an assertion failure, resulting in denial of service when under
high DNS-over-TLS query load conditions.

For the oldstable distribution (bullseye), these problems have been fixed
in version 1:9.16.44-1~deb11u1. The oldstable distribution (bullseye) is
only affected by CVE-2023-3341.

For the stable distribution (bookworm), these problems have been fixed in
version 1:9.18.19-1~deb12u1.

We recommend that you upgrade your bind9 packages.

For the detailed security status of bind9 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/source-package/bind9

Further information about Debian Security Advisories, how to apply
these updates to your system and frequ...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: bind9
CVE ID: CVE-2023-3341 CVE-2023-4236

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here