Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2024:2636-1 Important: Bind Security Update for DoS Risks

suse
Calendar Grey July 30, 2024
Dist Suse Esm H88
Important security patches for BIND address multiple vulnerabilities in SUSE distributions, guaranteeing essential corrections for server reliability.
* bsc#1228255 * bsc#1228256 * bsc#1228257 * bsc#1228258

Summary

## This update for bind fixes the following issues: Update to release 9.18.28 Security fixes: * CVE-2024-0760: Fixed a flood of DNS messages over TCP may make the server unstable (bsc#1228255) * CVE-2024-1737: Fixed BIND's database will be slow if a very large number of RRs exist at the same name (bsc#1228256) * CVE-2024-1975: Fixed SIG(0) can be used to exhaust CPU resources (bsc#1228257) * CVE-2024-4076: Fixed assertion failure when serving both stale cache data and authoritative zone content (bsc#1228258) Changelog: * Command-line options for IPv4-only (named -4) and IPv6-only (named -6) modes are now respected for zone primaries, also-notify, and parental-agents. * An RPZ response’s SOA record TTL was set to 1 instead of the SOA TTL, if add-soa was used. This has been fixed.

References

* bsc#1228255

* bsc#1228256

* bsc#1228257

* bsc#1228258

Cross-

* CVE-2024-0760

* CVE-2024-1737

* CVE-2024-1975

* CVE-2024-4076

CVSS scores:

* CVE-2024-0760 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-1737 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-1975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2024-4076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

* Basesystem Module 15-SP6

* openSUSE Leap 15.6

* Server Applications Module 15-SP6

* SUSE Linux Enterprise Desktop 15 SP6

* SUSE Linux Enterprise Real Time 15 SP6

* SUSE Linux Enterprise Server 15 SP6

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

An update that solves four vulnerabilities can now be installed.

##

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:2636-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here