Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2024:0574-2 Critical: Bind Service Disruption Resolutions

suse
Calendar Grey February 21, 2024
Dist Suse Esm H88
Patch release for bind in SUSE resolving various denial-of-service vulnerabilities with critical updates. Discover more.
* bsc#1219823 * bsc#1219826 * bsc#1219851 * bsc#1219852 * bsc#1219853

Summary

## This update for bind fixes the following issues: Update to release 9.16.48: * CVE-2023-50387: Fixed a denial-of-service caused by DNS messages containing a lot of DNSSEC signatures (bsc#1219823). * CVE-2023-50868: Fixed a denial-of-service caused by NSEC3 closest encloser proof (bsc#1219826). * CVE-2023-4408: Fixed a denial-of-service caused by DNS messages with many different names (bsc#1219851). * CVE-2023-5517: Fixed a possible crash when nxdomain-redirect was enabled (bsc#1219852). * CVE-2023-5679: Fixed a possible crash when bad interaction between DNS64 and serve-stale, when both of these features are enabled (bsc#1219853). * CVE-2023-6516: Fixed excessive memory consumption when continuously trigger the cache database maintenance (bsc#1219854). ## Patch Instructions:

References

* bsc#1219823

* bsc#1219826

* bsc#1219851

* bsc#1219852

* bsc#1219853

* bsc#1219854

Cross-

* CVE-2023-4408

* CVE-2023-50387

* CVE-2023-50868

* CVE-2023-5517

* CVE-2023-5679

* CVE-2023-6516

CVSS scores:

* CVE-2023-4408 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-50387 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-50387 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-50868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-5517 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-5679 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2023-6516 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP5

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:0574-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here