Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-3341

26
FAUCET Score

CVE-2023-3341 is a high-severity denial-of-service vulnerability affecting multiple versions of ISC BIND 9, including those distributed by Debian and Fedora. The flaw allows an unauthenticated attacker to crash the named daemon by sending specially crafted control channel messages, exploiting a recursive parsing vulnerability that exhausts stack memory. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network without requiring any authentication. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.2.0, < 9.16.44CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
>= 9.18.0, < 9.18.19CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
>= 9.19.0, < 9.19.17CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
9.9.3CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:*
9.9.12CPE matchmatch criteria
cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.63%
Probability of exploitation in next 30 days
EPSS Percentile
83.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0263 is in the 71st percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (27)

microsoftpatch availablevia msrc
Product: 18308-16823Fixed in: 9.16.44-1
microsoftpatch availablevia msrc
Product: 18309-17084Fixed in: 9.16.44-1
microsoftpatch availablevia msrc
Product: 17073-17084Fixed in: 9.19.21-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 9.19.21-1
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 9.19.21-1
microsoftpatch availablevia msrc
Product: cbl2 bind 9.16.44-1 on CBL Mariner 2.0Fixed in: 9.16.44-1
microsoftpatch availablevia msrc
Product: azl3 bind 9.16.44-1 on Azure Linux 3.0Fixed in: 9.16.44-1
microsoftpatch availablevia msrc
Product: azl3 bind 9.16.44-2 on Azure Linux 3.0Fixed in: 9.19.21-1
nessuspatch availablevia llm_extracted
Fixed in: 9.18.19-S1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: bind-32:9.11.13-6.el8_2.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: bind-32:9.11.13-6.el8_2.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: bind-32:9.11.13-6.el8_2.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: bind-32:9.11.26-4.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: bind-32:9.11.26-4.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: bind-32:9.11.26-4.el8_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: bind-32:9.11.36-3.el8_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Extended Update SupportFixed in: bind9.16-32:9.16.23-0.7.el8_6.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: bind-32:9.16.23-11.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: bind-32:9.16.23-1.el9_0.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: bind-32:9.11.36-8.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: bind9.16-32:9.16.23-0.14.el8_8.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionsFixed in: bind-32:9.11.4-26.P2.el8_1.8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONFixed in: bind-32:9.8.2-0.68.rc1.el6_10.14
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONFixed in: bind-dyndb-ldap-0:2.3-8.el6_10.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: bind-32:9.11.4-26.P2.el7_9.15
View patch
alistgovendor investigatingvia llm_extracted
View patch
consensysvendor investigatingvia llm_extracted
View patch

Vendor Advisories (6)

microsoft2024-Jun/CVE-2023-3341

CVE-2023-3341

Jun 11, 2024
redhatCVE-2023-3341Important

bind: stack exhaustion in control channel code may lead to DoS

Sep 20, 2023
microsoft2023-Sep/CVE-2023-3341Important

A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly

Sep 12, 2023
nessusllm-nessus-467f82875ceedc3c
alistgollm-alistgo-5ae93404342d15c1

A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly

consensysllm-consensys-143034dfd373d605

References

kb.isc.org / docs/cve-2023-3341
Vendor Advisory
lists.debian.org / debian-lts-announce/2024/01/msg00021.html
Third Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/IPJLLTJCSDJJII7IIZPLTBQNWP7MZH7F
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/U35OARLQCPMVCBBPHWBXY5M6XJLD2TZ5
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/VSK5V4W4OHPM3JTJGWAQD6CZW7SFD75B
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20231013-0003
Third Party Advisory
debian.org / security/2023/dsa-5504
Third Party Advisory
openwall.com / lists/oss-security/2023/09/20/2
Mailing ListPatch