CVE-2023-2828
published 2023-06-21CVE-2023-2828: Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.78%
88.8th percentile
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit.
It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded.
This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.
Affected
29 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.16-1~deb12u1 (bookworm) | bind9 1:9.18.16-1~deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | minio_console | >= 0 < 0.28.0 | 0.28.0 |
| isc | bind | 9.11.0 – 9.16.41 | — |
| isc | bind | 9.11.3 – 9.16.41 | — |
| isc | bind | 9.18.0 – 9.18.15 | — |
| isc | bind | 9.18.11 – 9.18.15 | — |
| isc | bind | 9.19.0 – 9.19.13 | — |
| isc | bind9 | >= 0 < 1:9.16.42-1~deb11u1 | 1:9.16.42-1~deb11u1 |
| isc | bind9 | >= 0 < 1:9.18.16-1~deb12u1 | 1:9.18.16-1~deb12u1 |
| isc | bind9 | >= 0 < 1:9.18.16-1 | 1:9.18.16-1 |
| isc | bind9 | >= 0 < 1:9.18.16-1 | 1:9.18.16-1 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.15 | 1:9.16.1-0ubuntu2.15 |
| isc | bind9 | >= 0 < 1:9.18.12-0ubuntu0.22.04.2 | 1:9.18.12-0ubuntu0.22.04.2 |
| isc | bind9 | >= 0 < 1:9.9.5.dfsg-3ubuntu0.19+esm10 | 1:9.9.5.dfsg-3ubuntu0.19+esm10 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.19+esm6 | 1:9.10.3.dfsg.P4-8ubuntu1.19+esm6 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.19+esm1 | 1:9.11.3+dfsg-1ubuntu1.19+esm1 |
| isc | bind_9 | 9.11.0 – 9.16.41 | — |
| isc | bind_9 | 9.11.3-S1 – 9.16.41-S1 | — |
| isc | bind_9 | 9.18.0 – 9.18.15 | — |
| isc | bind_9 | 9.18.11-S1 – 9.18.15-S1 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_redhat7.8HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
bind9 vulnerability
osv·2023-07-18·CVSS 7.5
CVE-2023-2828 [HIGH] bind9 vulnerability
bind9 vulnerability
USN-6183-1 fixed vulnerabilities in Bind. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04
LTS.
Original advisory details:
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled the cache size limit. A remote attacker could
possibly use this issue to consume memory, leading to a denial of service.
(CVE-2023-2828)
It was discovered that Bind incorrectly handled the recursive-clients
quota. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-2911)
OSV
CVE-2023-2828: Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent
osv·2023-06-21·CVSS 7.5
CVE-2023-2828 [HIGH] CVE-2023-2828: Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit. It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configu
GHSA
GHSA-v668-ccv8-m5gx: Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent
ghsa_unreviewed·2023-06-21
CVE-2023-2828 [HIGH] CWE-770 GHSA-v668-ccv8-m5gx: Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit.
It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the config
OSV
bind9 vulnerabilities
osv·2023-06-21·CVSS 7.5
CVE-2023-2828 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled the cache size limit. A remote attacker could
possibly use this issue to consume memory, leading to a denial of service.
(CVE-2023-2828)
It was discovered that Bind incorrectly handled the recursive-clients
quota. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-2911)
GHSA
Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited
ghsa·2023-05-26
CVE-2023-33955 [MEDIUM] CWE-200 Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited
Minio console object names with RIGHT-TO-LEFT OVERRIDE unicode character can be exploited
### Impact
Unicode RIGHT-TO-LEFT OVERRIDE characters can be used to mask the original filename.
### Reported-By
Thanks to the report from Mio Li [[email protected]](mailto:[email protected])
### Patches
```
commit 17e791afb90c9ad27c65f63c6be14f2f6a3a9d60
Author: Daniel Valdivia
Date: Tue May 23 08:47:12 2023 -0700
Replace RIGHT-TO-LEFT OVERRIDE unicode (#2828)
Signed-off-by: Daniel Valdivia
```
### Workarounds
Workarounds are to remove the concerned file and rewrite it properly with the right file and extensions. Avoid using RTLO characters in your filenames.
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
Ubuntu
Bind vulnerability
vendor_ubuntu·2023-07-18·CVSS 7.5
CVE-2023-2828 [HIGH] Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network traffic.
USN-6183-1 fixed vulnerabilities in Bind. This update provides the
corresponding updates for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04
LTS.
Original advisory details:
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled the cache size limit. A remote attacker could
possibly use this issue to consume memory, leading to a denial of service.
(CVE-2023-2828)
It was discovered that Bind incorrectly handled the recursive-clients
quota. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE
Red Hat
bind: named's configured cache size limit can be significantly exceeded
vendor_redhat·2023-06-21·CVSS 7.5
CVE-2023-2828 [HIGH] bind: named's configured cache size limit can be significantly exceeded
bind: named's configured cache size limit can be significantly exceeded
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit.
It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2023-06-21·CVSS 7.5
CVE-2023-2911 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Shoham Danino, Anat Bremler-Barr, Yehuda Afek, and Yuval Shavitt discovered
that Bind incorrectly handled the cache size limit. A remote attacker could
possibly use this issue to consume memory, leading to a denial of service.
(CVE-2023-2828)
It was discovered that Bind incorrectly handled the recursive-clients
quota. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04. (CVE-2023-2911)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
named's configured cache size limit can be significantly exceeded
vendor_msrc·2023-06-13·CVSS 7.5
CVE-2023-2828 [HIGH] CWE-770 named's configured cache size limit can be significantly exceeded
named's configured cache size limit can be significantly exceeded
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https:/
Debian
CVE-2023-2828: bind9 - Every `named` instance configured to run as a recursive resolver maintains a cac...
vendor_debian·2023·CVSS 7.5
CVE-2023-2828 [HIGH] CVE-2023-2828: bind9 - Every `named` instance configured to run as a recursive resolver maintains a cac...
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit. It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configu
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2023/06/21/6https://kb.isc.org/docs/cve-2023-2828https://lists.debian.org/debian-lts-announce/2023/07/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/SEFCEVCTYEMKTWA7V7EYPI5YQQ4JWDLI/https://lists.fedoraproject.org/archives/list/[email protected]/message/U3K6AJK7RRSR53HRF5GGKPA6PDUDWOD2/https://security.netapp.com/advisory/ntap-20230703-0010/https://www.debian.org/security/2023/dsa-5439http://www.openwall.com/lists/oss-security/2023/06/21/6https://kb.isc.org/docs/cve-2023-2828https://lists.debian.org/debian-lts-announce/2023/07/msg00021.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/SEFCEVCTYEMKTWA7V7EYPI5YQQ4JWDLI/https://lists.fedoraproject.org/archives/list/[email protected]/message/U3K6AJK7RRSR53HRF5GGKPA6PDUDWOD2/https://security.netapp.com/advisory/ntap-20230703-0010/https://www.debian.org/security/2023/dsa-5439
2023-06-21
Published