NA

CVE-2023-4236

Published: 20/09/2023 Updated: 01/02/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 up to and including 9.18.18 and 9.18.11-S1 up to and including 9.18.18-S1.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind 9.18.18

isc bind

isc bind 9.18.11

fedoraproject fedora 37

fedoraproject fedora 38

fedoraproject fedora 39

debian debian linux 10.0

debian debian linux 11.0

netapp h300s_firmware -

netapp h500s_firmware -

netapp h700s_firmware -

netapp h410s_firmware -

netapp h410c_firmware -

Vendor Advisories

Debian Bug report logs - #1052416 bind9: CVE-2023-3341 Package: src:bind9; Maintainer for src:bind9 is Debian DNS Team <team+dns@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Sep 2023 17:27:02 UTC Severity: grave Tags: security, upstream Found in versions bind9/1:91816-1~ ...
Debian Bug report logs - #1052417 bind9: CVE-2023-4236 Package: src:bind9; Maintainer for src:bind9 is Debian DNS Team <team+dns@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 21 Sep 2023 17:27:06 UTC Severity: grave Tags: security, upstream Found in versions bind9/1:91816-1, ...
Several vulnerabilities were discovered in BIND, a DNS server implementation CVE-2023-3341 A stack exhaustion flaw was discovered in the control channel code which may result in denial of service (named daemon crash) CVE-2023-4236 Robert Story discovered that a flaw in the networking code handling DNS-over-TLS queries could cause ...
Description<!---->A flaw was found in the Bind package The networking code handling DNS-over-TLS queries may cause named to terminate unexpectedly due to an assertion failure This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load A named instance vulnerable to this flaw may terminate unexpecte ...