BIND 9 DNS Parsing Complexity DoS (v9.0.0-9.19.19)
CVE-2023-4408 Published on February 13, 2024
Parsing large DNS messages may cause excessive CPU load
The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers.
This issue affects BIND 9 versions 9.0.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Vulnerability Analysis
CVE-2023-4408 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
Products Associated with CVE-2023-4408
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-4408 are published in these products:
Affected Versions
ISC BIND 9:- Version 9.0.0, <= 9.16.45 is affected.
- Version 9.18.0, <= 9.18.21 is affected.
- Version 9.19.0, <= 9.19.19 is affected.
- Version 9.9.3-S1, <= 9.11.37-S1 is affected.
- Version 9.16.8-S1, <= 9.16.45-S1 is affected.
- Version 9.18.11-S1, <= 9.18.21-S1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.