Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-1975
HistoryJul 23, 2024 - 12:00 a.m.

CVE-2024-1975

2024-07-2300:00:00
ubuntu.com
ubuntu.com
2
cve-2024-1975
cpu exhaustion
isc-dhcp
bind9-libs
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

19.5%

If a server hosts a zone containing a “KEY” Resource Record, or a resolver
DNSSEC-validates a “KEY” Resource Record from a DNSSEC-signed domain in
cache, a client can exhaust resolver CPU resources by sending a stream of
SIG(0) signed requests.
This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through
9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through
9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through
9.18.27-S1.

Notes

Author Note
alexmurray As of isc-dhcp-4.4.3-1, isc-dhcp vendors bind9 libs
mdeslaur in focal and jammy, isc-dhcp uses the bind9-libs package This is unlikely to affect isc-dhcp’s use of bind9-libs and the vendored bind9 libs, marking as negligible

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

19.5%