[ELSA-2024-5390] bind9.16 security update

Severity Important
Affected Packages 9
CVEs 3

[32:9.16.23-0.22]
- Minor fix of reclimit test backport (CVE-2024-1737)

[32:9.16.23-0.21]
- Backport addition of max-records-per-type and max-records-per-type options
(CVE-2024-1737)

[32:9.16.23-0.20]
- Resolve CVE-2024-1975
- Resolve CVE-2024-1737
- Resolve CVE-2024-4076
- Add ability to change runtime limits for max types and records per name

[32:9.16.23-0.19]
- Add few more explicit conflicts with bind subpackages (RHEL-2208)

[32:9.16.23-0.18]
- Prevent crashing at masterformat system test (CVE-2023-6516)

[32:9.16.23-0.17]
- Prevent increased CPU load on large DNS messages (CVE-2023-4408)
- Prevent assertion failure when nxdomain-redirect is used with
RFC 1918 reverse zones (CVE-2023-5517)
- Prevent assertion failure if DNS64 and serve-stale is used (CVE-2023-5679)
- Specific recursive query patterns may lead to an out-of-memory
condition (CVE-2023-6516)
- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
CVE-2023-50868)
- Import tests for large DNS messages fix
- Add downstream change complementing CVE-2023-50387

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/python3-bind9.16?distro=oraclelinux-8.10 oraclelinux python3-bind9.16 < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16?distro=oraclelinux-8.10 oraclelinux bind9.16 < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16-utils?distro=oraclelinux-8.10 oraclelinux bind9.16-utils < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16-license?distro=oraclelinux-8.10 oraclelinux bind9.16-license < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16-libs?distro=oraclelinux-8.10 oraclelinux bind9.16-libs < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16-doc?distro=oraclelinux-8.10 oraclelinux bind9.16-doc < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16-dnssec-utils?distro=oraclelinux-8.10 oraclelinux bind9.16-dnssec-utils < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16-devel?distro=oraclelinux-8.10 oraclelinux bind9.16-devel < 9.16.23-0.22.el8_10 oraclelinux-8.10
Affected pkg:rpm/oraclelinux/bind9.16-chroot?distro=oraclelinux-8.10 oraclelinux bind9.16-chroot < 9.16.23-0.22.el8_10 oraclelinux-8.10
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...