CVE-2024-1975

Source
https://cve.org/CVERecord?id=CVE-2024-1975
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-1975.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-1975
Downstream
ALPINE (1)
AZL (3)
BELL (1)
CGA (2)
CLSA (9)
DEBIAN (1)
MGASA (1)
OESA (6)
openSUSE (1)
RHSA (13)
RLSA (3)
SUSE (6)
UBUNTU (1)
Related
Published
2024-07-23T15:15:03Z
Modified
2026-04-16T04:33:01Z
Summary
[none]
Details

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1.

References

Affected packages