bind-9.11.36-8.el8.1
エラータID: AXSA:2023-6230:07
リリース日:
2023/07/18 Tuesday - 01:57
題名:
bind-9.11.36-8.el8.1
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- BIND には、キャッシュクリーニングアルゴリズムの有効性が著しく
低下してしまう問題があるため、リモートの攻撃者により、特定の
リソースレコードセットを特定の順番でリゾルバに問い合わせることを
介して、サービス拒否攻撃を可能とする脆弱性が存在します。
(CVE-2023-2828)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2023-2828
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit. It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit. It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.
追加情報:
N/A
ダウンロード:
SRPMS
- bind-9.11.36-8.el8.1.src.rpm
MD5: eb0efd22cc7eccd830861bb703c530ca
SHA-256: 63a760beac813577988eb1c4cfc242bd01bcd90d5c5be8a603343fdab6455201
Size: 8.15 MB
Asianux Server 8 for x86_64
- bind-9.11.36-8.el8.1.x86_64.rpm
MD5: a326eca5c27a8ee883b95e4536314372
SHA-256: 2b521b8fe8008b4a22c27a0efde9e6c06b7d68ebb97d7ff5704ea173328ff313
Size: 2.13 MB - bind-chroot-9.11.36-8.el8.1.x86_64.rpm
MD5: 0b9342b83d1bc0b17c608d97853cbbb4
SHA-256: d12f6102c63bc3f03a9ad9e483c3178d83b408fe3b14d99f9df9dc9438e3323a
Size: 104.97 kB - bind-devel-9.11.36-8.el8.1.i686.rpm
MD5: 64599b6ce3b373f72bd2cd9b680f39cd
SHA-256: e01cfe17e86dee435b844d48cf963b13afced3b8dafc39cb12301450415cf0c1
Size: 177.50 kB - bind-devel-9.11.36-8.el8.1.x86_64.rpm
MD5: 4a044328e5d8023d4a1ace19159ee172
SHA-256: 586ebecdd9223e09c249522fab0055150033aa8d41ad4c832e3fb2581889de22
Size: 177.48 kB - bind-export-devel-9.11.36-8.el8.1.i686.rpm
MD5: b9ce6e5e588659c24a0c26d8ffa29d83
SHA-256: d0c9e78d539767fb525829ca220da9a70347289649a9ebbdccaf9c9ac2155c57
Size: 406.73 kB - bind-export-devel-9.11.36-8.el8.1.x86_64.rpm
MD5: 83db8e0075925919f102b5a360694f5a
SHA-256: 3723e04e9e49528363d82bc54b0708016da478f4cb5291c83a834a2f919ec2de
Size: 406.75 kB - bind-export-libs-9.11.36-8.el8.1.i686.rpm
MD5: 700e7b376d6561da9c8628ff7f2baf24
SHA-256: a1067fc37767019e0a78b39a0dc77b9c16fb4c77c455de00a1d9a74392e9912c
Size: 1.21 MB - bind-export-libs-9.11.36-8.el8.1.x86_64.rpm
MD5: 217da29187b3c9b51523771560f66a40
SHA-256: 92c8bb0283e4666e2ebadb09f267278b579a34b5fb29e637363b12f460c4d842
Size: 1.14 MB - bind-libs-9.11.36-8.el8.1.i686.rpm
MD5: d1a61df8a39ba2d6e7bdbbf7f65590b5
SHA-256: a4998e264eba0afb8d64d666acd570683ee41879b9cb2f1af2b375c3448d7bab
Size: 179.92 kB - bind-libs-9.11.36-8.el8.1.x86_64.rpm
MD5: f96736358f4e8a23c16bff4c18008a17
SHA-256: f535506829b1f349c209e7e1a2688790d276a1ba1d8a7a6ef1303797b9eb07b6
Size: 174.46 kB - bind-libs-lite-9.11.36-8.el8.1.i686.rpm
MD5: f64226a20520e0da72828bef5d32fa06
SHA-256: c268bc6c5400513609ad86ea2c8400c3f024021842f931577df6116ea1819053
Size: 1.26 MB - bind-libs-lite-9.11.36-8.el8.1.x86_64.rpm
MD5: 9cb381b0961dba6f6186efd2d3bc82b9
SHA-256: 69b949f10d6e6863bd35da6d9e518fd3c957dbf489d721554e4ccb634adefc65
Size: 1.18 MB - bind-license-9.11.36-8.el8.1.noarch.rpm
MD5: 1600c49eea4e2547511b210cdf92b206
SHA-256: 37bc4f3604a155ecd1287717e9b96e9d9d66462ca07983bbc3b65f12f6a5896b
Size: 102.86 kB - bind-lite-devel-9.11.36-8.el8.1.i686.rpm
MD5: 47e45d8fc9efbfa4ed497e6e9a2bc85c
SHA-256: 39b1df6ee2d038001de2cd92084d8a9d1f1f802107b70380eae147f898ffbb52
Size: 399.99 kB - bind-lite-devel-9.11.36-8.el8.1.x86_64.rpm
MD5: 335fab330e33b1f2a399debfd42deb3c
SHA-256: c3d2689a3821af0221131ef4d7f335b3bc484832280eeb5d4b0362bf69d84c72
Size: 400.00 kB - bind-pkcs11-9.11.36-8.el8.1.x86_64.rpm
MD5: 6a53f70a4a35209caf1bf98b1e952e47
SHA-256: 23deebe8e8dd5d4f6ad7167dbafa2d50c8f2d39d9f9a4b346e2aa5718e137392
Size: 398.00 kB - bind-pkcs11-devel-9.11.36-8.el8.1.i686.rpm
MD5: 95a8d9759e55e71db578a24371607a3d
SHA-256: bfd68475db8f1e2cd409a992aed54925f3b6fcebf82c543cffac8465b61a65fb
Size: 115.07 kB - bind-pkcs11-devel-9.11.36-8.el8.1.x86_64.rpm
MD5: 6d2e6e2114d6b28c862afe5dcc3ade1c
SHA-256: 82df7b0a51390e8b938725b1569110c1aec2f71b2497cda46edeedd04d08ab46
Size: 115.06 kB - bind-pkcs11-libs-9.11.36-8.el8.1.i686.rpm
MD5: c35bff8a0f44aa2b914b564fb9747322
SHA-256: 5eb0cf6e2d9caa90867f62ba802bb2d275c2781d653984aa88ab42100955b290
Size: 1.21 MB - bind-pkcs11-libs-9.11.36-8.el8.1.x86_64.rpm
MD5: 98c973b1cfb17c68c093dad8ddc70abe
SHA-256: 0d85fb6c9ca939b4a738ca18fa232a6351e3e0eb9cac29a42f6bcfefb4b5c84a
Size: 1.13 MB - bind-pkcs11-utils-9.11.36-8.el8.1.x86_64.rpm
MD5: e23ed8d86234750d5c6c5ab4b0bf6bd5
SHA-256: cd0396908f8442a1b67b4f6cc00a2742db9c5d5652babfee88d65463554c5a12
Size: 260.07 kB - bind-sdb-9.11.36-8.el8.1.x86_64.rpm
MD5: 429a50063307e4f9a9fe5e75193541e8
SHA-256: f849905e60a8c4560e692a6114b8ed4034419012615fc6492dd14f23fab962a9
Size: 457.67 kB - bind-sdb-chroot-9.11.36-8.el8.1.x86_64.rpm
MD5: 5f3b23e84e7d14ef41d300df3212ce08
SHA-256: b6c13de40e41e04022b556fb80b27f2ef9cd1215a1cb56411b39faa2cc5f3c5e
Size: 104.61 kB - bind-utils-9.11.36-8.el8.1.x86_64.rpm
MD5: 851773fc9c96de802cd43ff89e664675
SHA-256: d5f128bddd7456d0fb408ab828c5ca683b7717e32e4c04e9aad661faad55fffa
Size: 451.69 kB - python3-bind-9.11.36-8.el8.1.noarch.rpm
MD5: c0f64e53e79060cb6fec087c8a93531d
SHA-256: c5cb97ebc9dfd5a15058a937a0d946d662b97dfbf124e7c9fee7a703389de140
Size: 150.12 kB