CVE-2024-11187
published 2025-01-29CVE-2024-11187: It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker…
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
15.47%
96.4th percentile
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.33-1~deb12u2 (bookworm) | bind9 1:9.18.33-1~deb12u2 (bookworm) |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind9 | >= 0 < 1:9.16.50-1~deb11u3 | 1:9.16.50-1~deb11u3 |
| isc | bind9 | >= 0 < 1:9.18.33-1~deb12u2 | 1:9.18.33-1~deb12u2 |
| isc | bind9 | >= 0 < 1:9.20.5-1 | 1:9.20.5-1 |
| isc | bind9 | >= 0 < 1:9.20.5-1 | 1:9.20.5-1 |
| isc | bind9 | >= 0 < 1:9.18.30-0ubuntu0.20.04.2 | 1:9.18.30-0ubuntu0.20.04.2 |
| isc | bind9 | >= 0 < 1:9.18.30-0ubuntu0.22.04.2 | 1:9.18.30-0ubuntu0.22.04.2 |
| isc | bind9 | >= 0 < 1:9.18.30-0ubuntu0.24.04.2 | 1:9.18.30-0ubuntu0.24.04.2 |
| isc | bind_9 | 9.11.0 – 9.11.37 | — |
| isc | bind_9 | 9.11.3-S1 – 9.11.37-S1 | — |
| isc | bind_9 | 9.16.0 – 9.16.50 | — |
| isc | bind_9 | 9.16.8-S1 – 9.16.50-S1 | — |
| isc | bind_9 | 9.18.0 – 9.18.32 | — |
| isc | bind_9 | 9.18.11-S1 – 9.18.32-S1 | — |
| isc | bind_9 | 9.20.0 – 9.20.4 | — |
| isc | bind_9 | 9.21.0 – 9.21.3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w8w2-83mf-6cp5: It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section
ghsa_unreviewed·2025-01-30
CVE-2024-11187 [HIGH] CWE-405 GHSA-w8w2-83mf-6cp5: It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
OSV
CVE-2024-11187: It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section
osv·2025-01-29·CVSS 7.5
CVE-2024-11187 [HIGH] CVE-2024-11187: It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
OSV
CVE-2024-11187: It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section
osv·2025-01-29·CVSS 7.5
CVE-2024-11187 [HIGH] CVE-2024-11187: It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
OSV
bind9 vulnerabilities
osv·2025-01-29·CVSS 7.5
CVE-2024-11187 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Toshifumi Sakaguchi discovered that Bind incorrectly handled many records
in the additional section. A remote attacker could possibly use this issue
to cause Bind to consume CPU resources, leading to a denial of service.
(CVE-2024-11187)
Jean-François Billaud discovered that the Bind DNS-over-HTTPS
implementation incorrectly handled a heavy query load. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2024-12705)
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2025-01-29·CVSS 7.5
CVE-2024-12705 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Toshifumi Sakaguchi discovered that Bind incorrectly handled many records
in the additional section. A remote attacker could possibly use this issue
to cause Bind to consume CPU resources, leading to a denial of service.
(CVE-2024-11187)
Jean-François Billaud discovered that the Bind DNS-over-HTTPS
implementation incorrectly handled a heavy query load. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2024-12705)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: bind9: Many records in the additional section cause CPU exhaustion
vendor_redhat·2025-01-29·CVSS 7.5
CVE-2024-11187 [HIGH] CWE-400 bind: bind9: Many records in the additional section cause CPU exhaustion
bind: bind9: Many records in the additional section cause CPU exhaustion
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
A flaw was found in the bind package where a crafted DNS zone may generate nume
Debian
CVE-2024-11187: bind9 - It is possible to construct a zone such that some queries to it will generate re...
vendor_debian·2024·CVSS 7.5
CVE-2024-11187 [HIGH] CVE-2024-11187: bind9 - It is possible to construct a zone such that some queries to it will generate re...
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
Scope: local
bookworm: resolved (fixed in 1:9.18.33-1~deb12u2)
bullseye: resolved (fixed in 1:9.16.50-1~deb11u3)
forky: resolved (fixed in 1:9.20.5-1)
sid
No detection rules found.
No public exploits indexed.
2025-01-29
Published