CVE-2023-50868
Published: 13 February 2024
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Notes
Author | Note |
---|---|
alexmurray | As of isc-dhcp-4.4.3-1, isc-dhcp vendors bind9 libs |
mdeslaur | This is unlikely to affect isc-dhcp's use of bind9-libs and the vendored bind9 libs, marking as negligible |
Priority
Status
Package | Release | Status |
---|---|---|
bind9 Launchpad, Ubuntu, Debian |
bionic |
Released
(1:9.11.3+dfsg-1ubuntu1.19+esm3)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
focal |
Released
(1:9.16.48-0ubuntu0.20.04.1)
|
|
jammy |
Released
(1:9.18.18-0ubuntu0.22.04.2)
|
|
mantic |
Released
(1:9.18.18-0ubuntu2.1)
|
|
noble |
Pending
(1:9.18.24-0ubuntu1)
|
|
trusty |
Released
(1:9.9.5.dfsg-3ubuntu0.19+esm12)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
upstream |
Released
(9.16.48,9.18.24,9.19.21)
|
|
xenial |
Released
(1:9.10.3.dfsg.P4-8ubuntu1.19+esm8)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
bind9-libs Launchpad, Ubuntu, Debian |
bionic |
Does not exist
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
mantic |
Does not exist
|
|
noble |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
xenial |
Does not exist
|
|
dnsmasq Launchpad, Ubuntu, Debian |
bionic |
Released
(2.90-0ubuntu0.18.04.1+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
focal |
Released
(2.90-0ubuntu0.20.04.1)
|
|
jammy |
Released
(2.90-0ubuntu0.22.04.1)
|
|
mantic |
Released
(2.90-0ubuntu0.23.10.1)
|
|
noble |
Released
(2.90-1)
|
|
trusty |
Needs triage
|
|
upstream |
Released
(2.90)
|
|
xenial |
Released
(2.90-0ubuntu0.16.04.1+esm1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only) |
|
isc-dhcp Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Not vulnerable
(code not present)
|
|
jammy |
Not vulnerable
(code not present)
|
|
mantic |
Needs triage
|
|
noble |
Needs triage
|
|
trusty |
Not vulnerable
(code not present)
|
|
upstream |
Needs triage
|
|
xenial |
Not vulnerable
(code not present)
|
|
knot-resolver Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
mantic |
Needs triage
|
|
noble |
Pending
(5.7.1-1)
|
|
trusty |
Does not exist
|
|
upstream |
Released
(5.7.1-1)
|
|
xenial |
Needs triage
|
|
pdns-recursor Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Needs triage
|
|
jammy |
Needs triage
|
|
mantic |
Needs triage
|
|
noble |
Pending
(4.9.3-1)
|
|
trusty |
Ignored
(end of standard support)
|
|
upstream |
Released
(4.9.3-1)
|
|
xenial |
Needs triage
|
|
unbound Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Released
(1.9.4-2ubuntu1.5)
|
|
jammy |
Released
(1.13.1-1ubuntu5.4)
|
|
mantic |
Released
(1.17.1-2ubuntu0.1)
|
|
noble |
Released
(1.19.1-1ubuntu1)
|
|
trusty |
Needs triage
|
|
upstream |
Released
(1.19.1-1)
|
|
xenial |
Needs triage
|
|
Patches: upstream: https://github.com/NLnetLabs/unbound/commit/92f2a1ca690a44880f4c4fa70a4b5a4b029aaf1c |
References
- https://kb.isc.org/docs/cve-2023-50868
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html
- https://www.knot-resolver.cz/2024-02-13-knot-resolver-5.7.1.html
- https://blog.powerdns.com/2024/02/13/powerdns-recursor-4-8-6-4-9-3-5-0-2-released
- https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/
- https://nlnetlabs.nl/downloads/unbound/CVE-2023-50387_CVE-2023-50868.txt
- https://ubuntu.com/security/notices/USN-6633-1
- https://ubuntu.com/security/notices/USN-6642-1
- https://ubuntu.com/security/notices/USN-6657-1
- https://ubuntu.com/security/notices/USN-6665-1
- https://ubuntu.com/security/notices/USN-6723-1
- https://www.cve.org/CVERecord?id=CVE-2023-50868
- https://ubuntu.com/security/notices/USN-6657-2
- NVD
- Launchpad
- Debian