bind-9.16.23-11.el9.1

エラータID: AXSA:2023-6228:06

Release date: 
Tuesday, July 18, 2023 - 09:31
Subject: 
bind-9.16.23-11.el9.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.

Security Fix(es):

* bind: named's configured cache size limit can be significantly exceeded (CVE-2023-2828)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-2828
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit. It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. bind-9.16.23-11.el9.1.src.rpm
    MD5: d5b72b4e5cee556f311c68574f7a2bb1
    SHA-256: 97b279b4d89079037285e922012d70b9e88c5bbde251f0a049784b731f02acf3
    Size: 4.97 MB

Asianux Server 9 for x86_64
  1. bind-9.16.23-11.el9.1.x86_64.rpm
    MD5: ae1fb2c6e9d70d0ea0592b5a237abddb
    SHA-256: 84a96598e45aab83eced8dfc36e5b14e30ccf104acb137dbf3a02f8f1d74620b
    Size: 487.74 kB
  2. bind-chroot-9.16.23-11.el9.1.x86_64.rpm
    MD5: 3ba9d1d3ca5c377af2332dbb9ff9e01e
    SHA-256: 2f2970caa579c8454e72b240e0e8a9fcb48f06a9f43636416cf33751e67f3082
    Size: 16.46 kB
  3. bind-devel-9.16.23-11.el9.1.i686.rpm
    MD5: 4a6638e307454cd08047afe9a91c1b89
    SHA-256: 4af9880d0410c7b54c67176926886247b833b16d1ed4194b7ceb07329d0480ae
    Size: 301.49 kB
  4. bind-devel-9.16.23-11.el9.1.x86_64.rpm
    MD5: d0ade61e03d3789141e1fd9b54c6b04d
    SHA-256: 1cca43481ef801cd0c854041497d6928c6955ba6983deabe61e2713b4205ff5a
    Size: 301.61 kB
  5. bind-dnssec-doc-9.16.23-11.el9.1.noarch.rpm
    MD5: 76ed4298c73fcc81d0c1e934d524bd04
    SHA-256: 629600ff1de3d51452fbd492d5802bd66e428f8af6a2753742d8a9c59809cb6e
    Size: 45.06 kB
  6. bind-dnssec-utils-9.16.23-11.el9.1.x86_64.rpm
    MD5: e04f37074ba149415c44d30f63c2ba8a
    SHA-256: 44ac9319feea868232bcb6c61d844ff65e4fcf3a4037e5327da01d64d14ab261
    Size: 112.54 kB
  7. bind-doc-9.16.23-11.el9.1.noarch.rpm
    MD5: c16b41c911eeb5a304a52ac67845d8a3
    SHA-256: 7ac4519584eaaeec145eb691330b95fc2f4d93b17c4bc9807ae23449eda3fff3
    Size: 2.07 MB
  8. bind-libs-9.16.23-11.el9.1.i686.rpm
    MD5: 873b0495c64a02d7fdf3b13045f5f45c
    SHA-256: f1e8577d3f3e9bc5246b50050eeae268021c43b4bc084cc965665a18bcbb29ff
    Size: 1.33 MB
  9. bind-libs-9.16.23-11.el9.1.x86_64.rpm
    MD5: 561c07f97b97a641bf6f8a65dd25ce7e
    SHA-256: 7ba32b2438f6b8da9715ae31bdd98d1edd4eb9f3ddd2ff6fad7cd8790acc1f03
    Size: 1.24 MB
  10. bind-license-9.16.23-11.el9.1.noarch.rpm
    MD5: e8d95d99b02eb259e924e0cec9c296b3
    SHA-256: 2970fa86fb836f0e1045dd670ccfdc400261a4be81198351c4626de24cfbc3b6
    Size: 12.58 kB
  11. bind-utils-9.16.23-11.el9.1.x86_64.rpm
    MD5: 6397e48356011f373dd0c24952ff4840
    SHA-256: 81ad1b156e0be1ee6a5675695441b542eff19868a51063e339b7f2216bc95968
    Size: 199.15 kB
  12. python3-bind-9.16.23-11.el9.1.noarch.rpm
    MD5: cc250d82e8bb9482562426cc5799bafb
    SHA-256: 0ba16d074a8fd349c3fafeb1e07f9f7469efa51aa7902511488fdb6fd82c5033
    Size: 60.60 kB