CVE-2024-11187: Many records in the additional section cause CPU exhaustion
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.
Other sources
Many records in the additional section cause CPU exhaustion
— Microsoft
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11187?
CVE-2024-11187 has been classified with a high severity rating due to potential denial of service impacts.
How do I fix CVE-2024-11187?
To resolve CVE-2024-11187, upgrade to secure versions 1:9.18.33-1~deb12u2 or 1:9.20.5-1 of the bind9 package.
What software is affected by CVE-2024-11187?
CVE-2024-11187 affects the bind9 package versions up to 1:9.16.50-1~deb11u2, 1:9.18.28-1~deb12u2, and 1:9.20.4-4.
Can CVE-2024-11187 be exploited remotely?
Yes, CVE-2024-11187 can potentially be exploited remotely by attackers sending specially crafted queries.
What are the consequences of CVE-2024-11187 exploitation?
Exploitation of CVE-2024-11187 may result in excessive resource consumption leading to service disruptions.