ALAS-2024-680


Amazon Linux 2023 Security Advisory: ALAS-2024-680
Advisory Release Date: 2024-08-01 04:06 Pacific
Advisory Updated Date: 2024-08-06 15:00 Pacific
Severity: Important

Issue Overview:

Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1. (CVE-2024-1737)

If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests.
This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.9.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.49-S1, and 9.18.11-S1 through 9.18.27-S1. (CVE-2024-1975)

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure.
This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1. (CVE-2024-4076)


Affected Packages:

bind


Issue Correction:
Run dnf update bind --releasever 2023.5.20240805 to update your system.

New Packages:
aarch64:
    bind-libs-debuginfo-9.18.28-1.amzn2023.0.1.aarch64
    bind-chroot-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-mysql-debuginfo-9.18.28-1.amzn2023.0.1.aarch64
    bind-dnssec-utils-debuginfo-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-mysql-9.18.28-1.amzn2023.0.1.aarch64
    bind-debuginfo-9.18.28-1.amzn2023.0.1.aarch64
    bind-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-sqlite3-9.18.28-1.amzn2023.0.1.aarch64
    bind-devel-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-ldap-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-filesystem-debuginfo-9.18.28-1.amzn2023.0.1.aarch64
    bind-dnssec-utils-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-sqlite3-debuginfo-9.18.28-1.amzn2023.0.1.aarch64
    bind-debugsource-9.18.28-1.amzn2023.0.1.aarch64
    bind-utils-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-filesystem-9.18.28-1.amzn2023.0.1.aarch64
    bind-utils-debuginfo-9.18.28-1.amzn2023.0.1.aarch64
    bind-libs-9.18.28-1.amzn2023.0.1.aarch64
    bind-dlz-ldap-debuginfo-9.18.28-1.amzn2023.0.1.aarch64

noarch:
    bind-doc-9.18.28-1.amzn2023.0.1.noarch
    bind-license-9.18.28-1.amzn2023.0.1.noarch

src:
    bind-9.18.28-1.amzn2023.0.1.src

x86_64:
    bind-libs-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-sqlite3-9.18.28-1.amzn2023.0.1.x86_64
    bind-utils-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-dnssec-utils-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-chroot-9.18.28-1.amzn2023.0.1.x86_64
    bind-devel-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-ldap-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-ldap-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-filesystem-9.18.28-1.amzn2023.0.1.x86_64
    bind-utils-9.18.28-1.amzn2023.0.1.x86_64
    bind-libs-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-sqlite3-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-filesystem-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-dnssec-utils-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-mysql-9.18.28-1.amzn2023.0.1.x86_64
    bind-debugsource-9.18.28-1.amzn2023.0.1.x86_64
    bind-dlz-mysql-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-debuginfo-9.18.28-1.amzn2023.0.1.x86_64
    bind-9.18.28-1.amzn2023.0.1.x86_64