CVE-2023-4408

Updated: 2025-03-18 22:11:46.851544

Description:

The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU dhcp 4.4.2 7.5 HIGH Released CLSA-2025:1741126840 2025-03-05 21:56:54 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
AlmaLinux 9.2 ESU bind 9.16.23 7.5 HIGH Released CLSA-2025:1739961948 2025-02-20 06:46:24 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 6 ELS dhcp 4.1.1 7.5 HIGH Not Vulnerable 2024-10-02 14:25:59 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 6 ELS bind 9.8.2 7.5 HIGH Not Vulnerable 2024-05-15 10:25:44 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 7 ELS dhcp 4.2.5 7.5 HIGH Not Vulnerable 2024-10-07 10:48:27 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 7 ELS bind 9.11.4 7.5 HIGH Released CLSA-2024:1720777628 2024-07-25 17:33:16 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 8.4 ELS bind 9.11.26 7.5 HIGH Released CLSA-2024:1717086870 2024-05-30 14:22:29 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 8.4 ELS dhcp 4.3.6-44 7.5 HIGH Not Vulnerable 2024-10-02 14:26:02 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 8.5 ELS bind 9.11.26 7.5 HIGH Released CLSA-2024:1717087024 2024-05-30 14:22:28 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
CentOS 8.5 ELS dhcp 4.3.6-45 7.5 HIGH Not Vulnerable 2024-10-02 14:26:02 We have reasoned not to port the patches for this CVE since the changes introduced are too intrusive
Total: 22