Bugzilla – Bug 1212609
VUL-0: CVE-2023-2829: bind: DNSSEC-Validated cache can be remotely terminated with malformed NSEC record
Last modified: 2023-06-23 07:31:56 UTC
CVE-2023-2829 A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1. https://kb.isc.org/docs/cve-2023-2829 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-2829 https://bugzilla.redhat.com/show_bug.cgi?id=2216581 https://www.cve.org/CVERecord?id=CVE-2023-2829 https://kb.isc.org/docs/cve-2023-2829
closing