Bug 2342879 (CVE-2024-11187)

Summary: CVE-2024-11187 bind: bind9: Many records in the additional section cause CPU exhaustion
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: vrajput
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in the bind package where a crafted DNS zone may generate numerous records in the 'Additional' section of the response. This flaw allows an attacker to send a large amount of such queries, which may lead either the authoritative server or an independent resolver to run into an uncontrolled CPU resource scenario, ultimately resulting in the server not being able to attend new requests and causing a denial of service as a consequence.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2342889, 2342890, 2342891, 2342892    
Bug Blocks:    

Description OSIDB Bzimport 2025-01-29 21:07:00 UTC
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.

Comment 3 errata-xmlrpc 2025-02-19 04:42:39 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:1664 https://access.redhat.com/errata/RHSA-2025:1664

Comment 4 errata-xmlrpc 2025-02-19 04:48:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2025:1665 https://access.redhat.com/errata/RHSA-2025:1665

Comment 5 errata-xmlrpc 2025-02-19 06:48:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:1666 https://access.redhat.com/errata/RHSA-2025:1666

Comment 6 errata-xmlrpc 2025-02-19 07:03:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:1669 https://access.redhat.com/errata/RHSA-2025:1669

Comment 7 errata-xmlrpc 2025-02-19 08:37:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:1670 https://access.redhat.com/errata/RHSA-2025:1670

Comment 8 errata-xmlrpc 2025-02-19 13:25:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:1676 https://access.redhat.com/errata/RHSA-2025:1676

Comment 9 errata-xmlrpc 2025-02-19 13:28:50 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7.7 Advanced Update Support

Via RHSA-2025:1674 https://access.redhat.com/errata/RHSA-2025:1674

Comment 10 errata-xmlrpc 2025-02-19 13:41:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:1675 https://access.redhat.com/errata/RHSA-2025:1675

Comment 11 errata-xmlrpc 2025-02-19 14:20:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:1679 https://access.redhat.com/errata/RHSA-2025:1679

Comment 12 errata-xmlrpc 2025-02-19 14:21:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Extended Update Support

Via RHSA-2025:1678 https://access.redhat.com/errata/RHSA-2025:1678

Comment 13 errata-xmlrpc 2025-02-19 14:44:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:1681 https://access.redhat.com/errata/RHSA-2025:1681

Comment 14 errata-xmlrpc 2025-02-19 15:54:38 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:1684 https://access.redhat.com/errata/RHSA-2025:1684

Comment 15 errata-xmlrpc 2025-02-19 17:28:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6 Extended Lifecycle Support  - EXTENSION

Via RHSA-2025:1685 https://access.redhat.com/errata/RHSA-2025:1685

Comment 16 errata-xmlrpc 2025-02-19 17:56:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2025:1687 https://access.redhat.com/errata/RHSA-2025:1687

Comment 17 errata-xmlrpc 2025-02-19 18:32:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Telecommunications Update Service
  Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions

Via RHSA-2025:1691 https://access.redhat.com/errata/RHSA-2025:1691

Comment 18 errata-xmlrpc 2025-02-20 09:36:36 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2025:1718 https://access.redhat.com/errata/RHSA-2025:1718

Comment 19 errata-xmlrpc 2025-03-05 03:51:51 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2025:1912 https://access.redhat.com/errata/RHSA-2025:1912

Comment 20 errata-xmlrpc 2025-03-05 04:00:04 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2025:1907 https://access.redhat.com/errata/RHSA-2025:1907

Comment 21 errata-xmlrpc 2025-03-13 05:47:02 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2025:2454 https://access.redhat.com/errata/RHSA-2025:2454

Comment 22 errata-xmlrpc 2025-03-13 16:30:07 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2025:2441 https://access.redhat.com/errata/RHSA-2025:2441

Comment 23 errata-xmlrpc 2025-03-19 20:55:11 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2025:2710 https://access.redhat.com/errata/RHSA-2025:2710

Comment 26 errata-xmlrpc 2025-04-16 06:12:40 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2025:3775 https://access.redhat.com/errata/RHSA-2025:3775