CVE-2023-5679

Updated: 2025-04-16 02:04:26.731075

Description:

A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU bind 9.16.23 7.5 HIGH Released CLSA-2025:1739386415 2025-02-13 01:27:03 Not affected
CentOS 6 ELS bind 9.8.2 7.5 HIGH Not Vulnerable 2024-04-25 21:42:06 Not affected
CentOS 7 ELS bind 9.11.4 7.5 HIGH Not Vulnerable 2024-04-23 10:07:00 Not affected
CentOS 8.4 ELS bind 9.11.26 7.5 HIGH Not Vulnerable 2024-05-30 14:22:27
CentOS 8.5 ELS bind 9.11.26 7.5 HIGH Not Vulnerable 2024-05-30 14:22:27 Not affected
CloudLinux 6 ELS bind 9.8.2 7.5 HIGH Not Vulnerable 2024-04-25 21:42:06 Not affected
Oracle Linux 6 ELS bind 9.8.2 7.5 HIGH Not Vulnerable 2024-04-25 21:42:06