Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 9: Critical Security Update for Bind Released (2025-0036)

mageia
Calendar Grey February 5, 2025
Dist Mageia Esm H88
Revised bind modules in Mageia resolve CPU strain and DNS complications stemming from extensive query traffic, in accordance with MGASA-2025-0036.
Many records in the additional section cause CPU exhaustion

Summary

Many records in the additional section cause CPU exhaustion. (CVE-2024-11187) DNS-over-HTTPS implementation suffers from multiple issues under heavy query load. (CVE-2024-12705)

References

- https://bugs.mageia.org/show_bug.cgi?id=33972

- https://www.openwall.com/lists/oss-security/2025/01/29/1

- https://www.cve.org/CVERecord?id=CVE-2024-11187

- https://www.cve.org/CVERecord?id=CVE-2024-12705

Resolution

SRPMS

- 9/core/bind-9.18.33-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 05 Feb 2025
URL: https://advisories.mageia.org/MGASA-2025-0036.html
Type: security
CVE: CVE-2024-11187, CVE-2024-12705

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here