CVE-2024-4076: Assertion failure when serving both stale cache data and authoritative zone content
Assertion failure when serving both stale cache data and authoritative zone content
Other sources
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.
— NVD
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This vulnerability affects upstream's bind9 versions bellow: 9.16.13 -> 9.16.50 9.18.0 -> 9.18.27 9.19.0 -> 9.19.24
— Red Hat
ISC BIND is vulnerable to a denial of service, caused by an error when serving both stale cache data and authoritative zone content. By sending queries, a remote attacker could exploit this vulnerability to cause an assertion failure.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4076?
CVE-2024-4076 is considered a high severity vulnerability due to the potential for assertion failure leading to service disruption.
How do I fix CVE-2024-4076?
To fix CVE-2024-4076, upgrade to BIND 9 versions 9.16.51, 9.18.28, 9.19.25, or later.
Which BIND 9 versions are affected by CVE-2024-4076?
CVE-2024-4076 affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, and 9.19.0 through 9.19.24.
Is my system vulnerable to CVE-2024-4076?
If you are running BIND 9 versions within the specified ranges, your system is vulnerable to CVE-2024-4076.
What impact does CVE-2024-4076 have on services?
CVE-2024-4076 may lead to assertion failures that can disrupt DNS services, potentially affecting network resolution.