The processing of responses coming from specially crafted DNSSEC-signed zones can cause CPU exhaustion on a DNSSEC-validating resolver.
Created bind tracking bugs for this issue: Affects: fedora-all [bug 2264067]
Quite surprising information for me. This seems to have been coordinated among multiple vendors. This is issue not only in BIND9, but any validating resolvers it seems! Found out just by coincidence at: https://fosstodon.org/@tychotithonus@infosec.exchange/111924626751024210 - unbound is affected as well: https://github.com/NLnetLabs/unbound/releases/tag/release-1.19.1 - dnsmasq is affected too: https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html Somehow I expect systemd-resolved to be affected too, when everyone else is.
ISC article about this issue: https://kb.isc.org/docs/cve-2023-50387
Created dnsmasq tracking bugs for this issue: Affects: fedora-all [bug 2264103] Created unbound tracking bugs for this issue: Affects: fedora-all [bug 2264104]
pdns-recursor is affected too
Discoverer of this issue has released also their press release: https://www.athene-center.de/en/news/press/key-trap
Created dhcp tracking bugs for this issue: Affects: fedora-all [bug 2264363]
Created pdns-recursor tracking bugs for this issue: Affects: epel-all [bug 2264397] Affects: fedora-all [bug 2264396]
Knot resolver is affected as well: https://www.knot-resolver.cz/2024-02-13-knot-resolver-5.7.1.html
Another post were published on labs.ripe.net: https://labs.ripe.net/author/haya-shulman/keytrap-algorithmic-complexity-attacks-exploit-fundamental-design-flaw-in-dnssec/ Published on dns-operations list: https://lists.dns-oarc.net/pipermail/dns-operations/2024-February/022436.html ISC has published also great summary on their blog: https://www.isc.org/blogs/2024-bind-security-release/
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:0965 https://access.redhat.com/errata/RHSA-2024:0965
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:0977 https://access.redhat.com/errata/RHSA-2024:0977
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:0981 https://access.redhat.com/errata/RHSA-2024:0981
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:0982 https://access.redhat.com/errata/RHSA-2024:0982
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1334 https://access.redhat.com/errata/RHSA-2024:1334
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1335 https://access.redhat.com/errata/RHSA-2024:1335
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:1522 https://access.redhat.com/errata/RHSA-2024:1522
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2024:1543 https://access.redhat.com/errata/RHSA-2024:1543
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:1544 https://access.redhat.com/errata/RHSA-2024:1544
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:1545 https://access.redhat.com/errata/RHSA-2024:1545
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:1647 https://access.redhat.com/errata/RHSA-2024:1647
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:1648 https://access.redhat.com/errata/RHSA-2024:1648
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1781 https://access.redhat.com/errata/RHSA-2024:1781
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:1782 https://access.redhat.com/errata/RHSA-2024:1782
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:1789 https://access.redhat.com/errata/RHSA-2024:1789
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2024:1801 https://access.redhat.com/errata/RHSA-2024:1801
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Extended Update Support Via RHSA-2024:1800 https://access.redhat.com/errata/RHSA-2024:1800
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:1804 https://access.redhat.com/errata/RHSA-2024:1804
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Extended Update Support Via RHSA-2024:1803 https://access.redhat.com/errata/RHSA-2024:1803
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:2551 https://access.redhat.com/errata/RHSA-2024:2551
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Via RHSA-2024:2587 https://access.redhat.com/errata/RHSA-2024:2587
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Red Hat Enterprise Linux 8.2 Telecommunications Update Service Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions Via RHSA-2024:2696 https://access.redhat.com/errata/RHSA-2024:2696
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Extended Update Support Via RHSA-2024:2720 https://access.redhat.com/errata/RHSA-2024:2720
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Extended Update Support Via RHSA-2024:2721 https://access.redhat.com/errata/RHSA-2024:2721
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Red Hat Enterprise Linux 8.4 Telecommunications Update Service Via RHSA-2024:2821 https://access.redhat.com/errata/RHSA-2024:2821
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2024:2890 https://access.redhat.com/errata/RHSA-2024:2890
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2024:3271 https://access.redhat.com/errata/RHSA-2024:3271
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2024:3741 https://access.redhat.com/errata/RHSA-2024:3741
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Telecommunications Update Service Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions Via RHSA-2024:3877 https://access.redhat.com/errata/RHSA-2024:3877
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2024:3929 https://access.redhat.com/errata/RHSA-2024:3929