RHSA-2023:5771HighCVSS 7.5
Red Hat Security Advisory: bind9.16 security update
🔗 CVE IDs covered (1)
📋 Description
CVE-2023-3341 — bind: stack exhaustion in control channel code may lead to DoS
🎯 Affected products77
- Red Hat CodeReady Linux Builder EUS (v.8.6)
- Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-32:9.16.23-0.7.el8_6.3.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-32:9.16.23-0.7.el8_6.3.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-32:9.16.23-0.7.el8_6.3.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-32:9.16.23-0.7.el8_6.3.src as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-32:9.16.23-0.7.el8_6.3.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-chroot-32:9.16.23-0.7.el8_6.3.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-chroot-32:9.16.23-0.7.el8_6.3.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-chroot-32:9.16.23-0.7.el8_6.3.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-chroot-32:9.16.23-0.7.el8_6.3.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.i686 as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debuginfo-32:9.16.23-0.7.el8_6.3.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.i686 as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- bind9.16-debugsource-32:9.16.23-0.7.el8_6.3.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.8.6)
- bind9.16-devel-32:9.16.23-0.7.el8_6.3.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.8.6)
- +47 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: By default, named only allows control-channel connections over the loopback interface, making this attack impossible to carry out over the network. When enabling remote access to the control channel’s configured TCP port, care should be taken to limit such access to trusted IP ranges on the network level, effectively preventing unauthorized parties from carrying out the attack described in this advisory.