Severity
7.5HIGH
EPSS
0.2%
top 59.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 21
Latest updateJul 18

Description

If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33 through 9.16.41, 9.18.7 through 9.18.15, 9.16.33-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Alpinebind< 9.16.42-r0
Debianbind9< 1:9.16.42-1~deb11u1+3
NVDisc/bind9.16.339.16.41+2
CVEListV5isc/bind_99.16.339.16.41+3

Also affects: Debian Linux 11.0, 12.0, Fedora 37, 38

Patches

🔴Vulnerability Details

6
OSV
bind9 vulnerability2023-07-18
OSV
CVE-2023-2911: If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`,2023-06-21
GHSA
GHSA-rrr5-v5h9-fpwp: If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`,2023-06-21
OSV
CVE-2023-2911: If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`,2023-06-21
CVEList
Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 02023-06-21

📋Vendor Advisories

4
Red Hat
bind: Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 02023-06-21
Ubuntu
Bind vulnerabilities2023-06-21
Microsoft
Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 02023-06-13
Debian
CVE-2023-2911: bind9 - If the `recursive-clients` quota is reached on a BIND 9 resolver configured with...2023