CVE-2023-4236 is a high-severity denial-of-service vulnerability affecting BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1, including distributions from Debian, Fedora, and NetApp. This flaw in the networking code can cause the named service to terminate unexpectedly due to an assertion failure when processing DNS-over-TLS queries under significant load. With a CVSS score of 7.5, it is easily exploitable over the network with low attack complexity, leading to a complete loss of availability. Currently, there is no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.18.0, < 9.18.18CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
9.18.11CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.18.11:s1:*:*:supported_preview:*:*:* | ||
9.18.18CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.18.18:s1:*:*:supported_preview:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.