CVE-2024-12705
published 2025-01-29CVE-2024-12705: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue…
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
17.94%
96.9th percentile
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.33-1~deb12u2 (bookworm) | bind9 1:9.18.33-1~deb12u2 (bookworm) |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind | >= 0 < 9.18.33-r0 | 9.18.33-r0 |
| isc | bind9 | >= 0 < 1:9.18.33-1~deb12u2 | 1:9.18.33-1~deb12u2 |
| isc | bind9 | >= 0 < 1:9.20.5-1 | 1:9.20.5-1 |
| isc | bind9 | >= 0 < 1:9.20.5-1 | 1:9.20.5-1 |
| isc | bind9 | >= 0 < 1:9.18.30-0ubuntu0.20.04.2 | 1:9.18.30-0ubuntu0.20.04.2 |
| isc | bind9 | >= 0 < 1:9.18.30-0ubuntu0.22.04.2 | 1:9.18.30-0ubuntu0.22.04.2 |
| isc | bind9 | >= 0 < 1:9.18.30-0ubuntu0.24.04.2 | 1:9.18.30-0ubuntu0.24.04.2 |
| isc | bind_9 | 9.18.0 – 9.18.32 | — |
| isc | bind_9 | 9.18.11-S1 – 9.18.32-S1 | — |
| isc | bind_9 | 9.20.0 – 9.20.4 | — |
| isc | bind_9 | 9.21.0 – 9.21.3 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gf34-2fpp-vmc4: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic
ghsa_unreviewed·2025-01-30
CVE-2024-12705 [HIGH] CWE-770 GHSA-gf34-2fpp-vmc4: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
OSV
CVE-2024-12705: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic
osv·2025-01-29·CVSS 7.5
CVE-2024-12705 [HIGH] CVE-2024-12705: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
OSV
CVE-2024-12705: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic
osv·2025-01-29·CVSS 7.5
CVE-2024-12705 [HIGH] CVE-2024-12705: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
OSV
bind9 vulnerabilities
osv·2025-01-29·CVSS 7.5
CVE-2024-11187 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Toshifumi Sakaguchi discovered that Bind incorrectly handled many records
in the additional section. A remote attacker could possibly use this issue
to cause Bind to consume CPU resources, leading to a denial of service.
(CVE-2024-11187)
Jean-François Billaud discovered that the Bind DNS-over-HTTPS
implementation incorrectly handled a heavy query load. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2024-12705)
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2025-01-29·CVSS 7.5
CVE-2024-12705 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Toshifumi Sakaguchi discovered that Bind incorrectly handled many records
in the additional section. A remote attacker could possibly use this issue
to cause Bind to consume CPU resources, leading to a denial of service.
(CVE-2024-11187)
Jean-François Billaud discovered that the Bind DNS-over-HTTPS
implementation incorrectly handled a heavy query load. A remote attacker
could possibly use this issue to cause Bind to consume resources, leading
to a denial of service. (CVE-2024-12705)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load
vendor_redhat·2024-01-29·CVSS 7.5
CVE-2024-12705 [HIGH] CWE-400 bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load
bind: bind9: DNS-over-HTTPS implementation suffers from multiple issues under heavy query load
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic.
This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
A flaw was found in BIND 9. By flooding a target resolver with HTTP/2 traffic and exploiting this flaw, an attacker could overwhelm the server, causing high CPU and/or memory usage and preventing other clients from establishing DoH connections. This issue could significantly impair the resolver's performance and effectively deny legitimate clients access to the DNS resolution service.
Statement: The bind package shi
Debian
CVE-2024-12705: bind9 - Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memor...
vendor_debian·2024·CVSS 7.5
CVE-2024-12705 [HIGH] CVE-2024-12705: bind9 - Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memor...
Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
Scope: local
bookworm: resolved (fixed in 1:9.18.33-1~deb12u2)
bullseye: resolved
forky: resolved (fixed in 1:9.20.5-1)
sid: resolved (fixed in 1:9.20.5-1)
trixie: resolved (fixed in 1:9.20.5-1)
No detection rules found.
No public exploits indexed.
2025-01-29
Published