CVE-2024-0760 is a high-severity denial-of-service vulnerability affecting specific versions of BIND 9, where a malicious client can destabilize the server by sending numerous DNS messages over TCP. The attack requires no authentication or user interaction, and while the server may recover, ACLs offer no mitigation. With a CVSS score of 7.5, the vulnerability has a high potential impact on availability. Currently, there is no public exploit code available, nor is it listed on the CISA KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ISC | BIND 9 | >= 9.18.1, <= 9.18.27, >= 9.18.11-S1, <= 9.18.27-S1, >= 9.19.0, <= 9.19.24CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024bind: bind9: A flood of DNS messages over TCP may make the server unstable
Jul 23, 2024A flood of DNS messages over TCP may make the server unstable
Jul 9, 2024A flood of DNS messages over TCP may make the server unstable