Lucene search

K
f5F5F5:K000137038
HistorySep 28, 2023 - 12:00 a.m.

K000137038 : BIND vulnerability CVE-2023-4236

2023-09-2800:00:00
my.f5.com
11
bind
vulnerability
denial-of-service
dns-over-tls
query load

7 High

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

35.0%

Security Advisory Description

A flaw in the networking code handling DNS-over-TLS queries may cause named to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1. (CVE-2023-4236)

Impact

The vulnerability may allow a remote unauthenticated attacker to cause a denial-of-service (DoS) on the Traffix SDC system.