CVE-2023-4236: named may terminate unexpectedly under high DNS-over-TLS query load
A flaw in the networking code handling DNS-over-TLS queries may cause named to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-4236?
CVE-2023-4236 is a vulnerability in BIND 9, the DNS server software developed by ISC.
How does CVE-2023-4236 affect BIND 9?
CVE-2023-4236 affects BIND 9 versions 9.18.0 through 9.18.18.
What is the severity of CVE-2023-4236?
The severity of CVE-2023-4236 is rated as high, with a CVSS score of 7.5.
What is the impact of CVE-2023-4236?
CVE-2023-4236 may cause the 'named' process to terminate unexpectedly due to an assertion failure, leading to a denial of service (DoS) condition.
How can I mitigate CVE-2023-4236?
To mitigate CVE-2023-4236, it is recommended to update BIND 9 to a version that includes the necessary fixes, such as 9.18.19.