Amazon Linux 2 Security Advisory: ALAS-2024-2616
Advisory Release Date: 2024-08-01 03:01 Pacific
Advisory Updated Date: 2024-08-13 09:45 Pacific
Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1. (CVE-2024-1737)
If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests.
This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1. (CVE-2024-1975)
Affected Packages:
bind
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update bind to update your system.
aarch64:
bind-9.11.4-26.P2.amzn2.13.7.aarch64
bind-pkcs11-9.11.4-26.P2.amzn2.13.7.aarch64
bind-pkcs11-utils-9.11.4-26.P2.amzn2.13.7.aarch64
bind-pkcs11-libs-9.11.4-26.P2.amzn2.13.7.aarch64
bind-pkcs11-devel-9.11.4-26.P2.amzn2.13.7.aarch64
bind-sdb-9.11.4-26.P2.amzn2.13.7.aarch64
bind-libs-lite-9.11.4-26.P2.amzn2.13.7.aarch64
bind-libs-9.11.4-26.P2.amzn2.13.7.aarch64
bind-utils-9.11.4-26.P2.amzn2.13.7.aarch64
bind-devel-9.11.4-26.P2.amzn2.13.7.aarch64
bind-lite-devel-9.11.4-26.P2.amzn2.13.7.aarch64
bind-chroot-9.11.4-26.P2.amzn2.13.7.aarch64
bind-sdb-chroot-9.11.4-26.P2.amzn2.13.7.aarch64
bind-export-libs-9.11.4-26.P2.amzn2.13.7.aarch64
bind-export-devel-9.11.4-26.P2.amzn2.13.7.aarch64
bind-debuginfo-9.11.4-26.P2.amzn2.13.7.aarch64
i686:
bind-9.11.4-26.P2.amzn2.13.7.i686
bind-pkcs11-9.11.4-26.P2.amzn2.13.7.i686
bind-pkcs11-utils-9.11.4-26.P2.amzn2.13.7.i686
bind-pkcs11-libs-9.11.4-26.P2.amzn2.13.7.i686
bind-pkcs11-devel-9.11.4-26.P2.amzn2.13.7.i686
bind-sdb-9.11.4-26.P2.amzn2.13.7.i686
bind-libs-lite-9.11.4-26.P2.amzn2.13.7.i686
bind-libs-9.11.4-26.P2.amzn2.13.7.i686
bind-utils-9.11.4-26.P2.amzn2.13.7.i686
bind-devel-9.11.4-26.P2.amzn2.13.7.i686
bind-lite-devel-9.11.4-26.P2.amzn2.13.7.i686
bind-chroot-9.11.4-26.P2.amzn2.13.7.i686
bind-sdb-chroot-9.11.4-26.P2.amzn2.13.7.i686
bind-export-libs-9.11.4-26.P2.amzn2.13.7.i686
bind-export-devel-9.11.4-26.P2.amzn2.13.7.i686
bind-debuginfo-9.11.4-26.P2.amzn2.13.7.i686
noarch:
bind-license-9.11.4-26.P2.amzn2.13.7.noarch
src:
bind-9.11.4-26.P2.amzn2.13.7.src
x86_64:
bind-9.11.4-26.P2.amzn2.13.7.x86_64
bind-pkcs11-9.11.4-26.P2.amzn2.13.7.x86_64
bind-pkcs11-utils-9.11.4-26.P2.amzn2.13.7.x86_64
bind-pkcs11-libs-9.11.4-26.P2.amzn2.13.7.x86_64
bind-pkcs11-devel-9.11.4-26.P2.amzn2.13.7.x86_64
bind-sdb-9.11.4-26.P2.amzn2.13.7.x86_64
bind-libs-lite-9.11.4-26.P2.amzn2.13.7.x86_64
bind-libs-9.11.4-26.P2.amzn2.13.7.x86_64
bind-utils-9.11.4-26.P2.amzn2.13.7.x86_64
bind-devel-9.11.4-26.P2.amzn2.13.7.x86_64
bind-lite-devel-9.11.4-26.P2.amzn2.13.7.x86_64
bind-chroot-9.11.4-26.P2.amzn2.13.7.x86_64
bind-sdb-chroot-9.11.4-26.P2.amzn2.13.7.x86_64
bind-export-libs-9.11.4-26.P2.amzn2.13.7.x86_64
bind-export-devel-9.11.4-26.P2.amzn2.13.7.x86_64
bind-debuginfo-9.11.4-26.P2.amzn2.13.7.x86_64