## This update for bind fixes the following issues: Update to release 9.18.28 Security fixes: * CVE-2024-0760: Fixed a flood of DNS messages over TCP may make the server unstable (bsc#1228255) * CVE-2024-1737: Fixed BIND's database will be slow if a very large number of RRs exist at the same name (bsc#1228256) * CVE-2024-1975: Fixed SIG(0) can be used to exhaust CPU resources (bsc#1228257) * CVE-2024-4076: Fixed assertion failure when serving both stale cache data and authoritative zone content (bsc#1228258) Changelog: * Command-line options for IPv4-only (named -4) and IPv6-only (named -6) modes are now respected for zone primaries, also-notify, and parental-agents. * An RPZ responseâs SOA record TTL was set to 1 instead of the SOA TTL, if add-soa was used. This has been fixed.
* bsc#1228255
* bsc#1228256
* bsc#1228257
* bsc#1228258
Cross-
* CVE-2024-0760
* CVE-2024-1737
* CVE-2024-1975
* CVE-2024-4076
CVSS scores:
* CVE-2024-0760 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-1737 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-1975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-4076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products:
* Basesystem Module 15-SP6
* openSUSE Leap 15.6
* Server Applications Module 15-SP6
* SUSE Linux Enterprise Desktop 15 SP6
* SUSE Linux Enterprise Real Time 15 SP6
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
An update that solves four vulnerabilities can now be installed.
##
Get the latest Linux and open source security news straight to your inbox.