Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Slackware 15.0: 2024-044-01 Critical: Bind Denial Of Service

slackware
Calendar Grey February 13, 2024
Dist Slackware Esm H88
A fresh bind update has been released for Slackware 15.0 to resolve urgent security vulnerabilities and improve the reliability of DNS services.
New bind packages are available for Slackware 15.0 and -current to fix security issues

Summary

Here are the details from the Slackware 15.0 ChangeLog: patches/packages/bind-9.16.48-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and security issues: Specific DNS answers could cause a denial-of-service condition due to DNS validation taking a long time. Query patterns that continuously triggered cache database maintenance could exhaust all available memory on the host running named. Restore DNS64 state when handling a serve-stale timeout. Specific queries could trigger an assertion check with nxdomain-redirect enabled. Speed up parsing of DNS messages with many different names. For more information, see: https://kb.isc.org/docs/cve-2023-50387 https://www.cve.org/CVERecord?id=CVE-2023-50387 https://kb.isc.org/docs/cve-2023-6516 https://www.cve.org/CVERecord?id=CVE-2023-6516 https://kb.isc.org/docs/cve-2023-5679 https://www.cve.org/CVERecord?id=CVE-2023-5679 https://kb.isc.org/docs/cve-2023-5517

Read the Full Advisory

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 15.0:
Updated package for Slackware x86_64 15.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 15.0 package: 688d05942acae07ca040a07057f107af bind-9.16.48-i586-1_slack15.0.txz
Slackware x86_64 15.0 package: 72ec1aa452c6b37046e74b90797be3e8 bind-9.16.48-x86_64-1_slack15.0.txz
Slackware -current package: 8e3c11dba6a01af76aa89531c2e2d62a n/bind-9.18.24-i586-1.txz
Slackware x86_64 -current package: 8a9d10f4a4f1501ffc7f087dec4e281e n/bind-9.18.24-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg bind-9.16.48-i586-1_slack15.0.txz Then, restart the name server: # /etc/rc.d/rc.bind restart

Your message here