CVE-2024-1975

Updated: 2025-08-20 01:46:28.411752

Description:

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 7 ELS bind 9.11.4 7.5 HIGH Already Fixed 2024-12-09 11:55:23
RHEL 7 ELS bind 9.11.4 7.5 HIGH Released CLSA-2025:1755512368 2025-08-19 06:33:24
Ubuntu 16.04 ELS bind9 9.10.3 7.5 HIGH Released CLSA-2024:1725471213 2024-09-04 14:23:03
Ubuntu 18.04 ELS bind9 9.11.3 7.5 HIGH Released CLSA-2024:1725993824 2024-09-10 17:26:11
Total: 14