cbcvebase.
CVE-2024-0760
published 2024-07-23

CVE-2024-0760: A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may…

PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.68%
90.8th percentile
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianbind9< bind9 1:9.18.28-1~deb12u1 (bookworm)bind9 1:9.18.28-1~deb12u1 (bookworm)
iscbind>= 0 < 9.18.31-r09.18.31-r0
iscbind>= 0 < 9.18.31-r09.18.31-r0
iscbind>= 0 < 9.18.31-r09.18.31-r0
iscbind>= 0 < 9.18.31-r09.18.31-r0
iscbind>= 0 < 9.18.28-r09.18.28-r0
iscbind>= 0 < 9.18.28-r09.18.28-r0
iscbind>= 0 < 9.18.28-r09.18.28-r0
iscbind9>= 0 < 1:9.18.28-1~deb12u11:9.18.28-1~deb12u1
iscbind9>= 0 < 1:9.20.0-11:9.20.0-1
iscbind9>= 0 < 1:9.20.0-11:9.20.0-1
iscbind9>= 0 < 1:9.18.28-0ubuntu0.20.04.11:9.18.28-0ubuntu0.20.04.1
iscbind9>= 0 < 1:9.18.28-0ubuntu0.22.04.11:9.18.28-0ubuntu0.22.04.1
iscbind9>= 0 < 1:9.18.28-0ubuntu0.24.04.11:9.18.28-0ubuntu0.24.04.1
iscbind_99.18.1 – 9.18.27
iscbind_99.18.11-S1 – 9.18.27-S1
iscbind_99.19.0 – 9.19.24
msrcazl3_bind_9.19.21-1_on_azure_linux_3.0
msrcazl3_bind_9.20.0-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.