ISC Product Security Update Advisory (CVE-2024-11187)

Overview

We have released security updates to fix vulnerabilities in ISC products. Users of affected products are advised to update to the latest version.
 

 

Affected Products

 

CVE-2024-11187

ISC BIND 9 Versions: 9.11.0 through 9.11.37 (excluded)
ISC BIND 9 Versions: 9.16.0 through 9.16.50 (excluded)
ISC BIND 9 versions: 9.18.0 through 9.18.32 (excluded)
ISC BIND 9 versions: 9.20.0 through 9.20.4 (excluded)
ISC BIND 9 versions: 9.21.0 through 9.21.3 (excluded)
ISC BIND 9 versions: 9.11.3-S1 through 9.11.37-S1 (excluded)
ISC BIND 9 versions: 9.16.8-S1 through 9.16.50-S1 (excluded)
ISC BIND 9 versions: 9.18.11-S1 through 9.18.32-S1 (excluded)

 

 

Resolved Vulnerabilities

Vulnerability where multiple records in the append section cause excessive CPU consumption (CVE-2024-11187)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-11187

ISC BIND 9 Version: 9.11.37
ISC BIND 9 Version: 9.16.50
ISC BIND 9 Version: 9.18.32
ISC BIND 9 Version: 9.20.4
ISC BIND 9 Version: 9.21.3
ISC BIND 9 Version: 9.11.37-S1
ISC BIND 9 Version: 9.16.50-S1
ISC BIND 9 Version: 9.18.32-S1

 

References

[1] CVE-2024-11187
https://www.cve.org/CVERecord?id=CVE-2024-11187
[2] CVE-2024-11187: Many records in the additional section cause CPU exhaustion
https://kb.isc.org/docs/cve-2024-11187