CVE-2024-4076 is a high-severity denial-of-service vulnerability affecting multiple versions of BIND 9, specifically impacting client queries that trigger stale data serving and require local authoritative zone lookups. This can lead to an assertion failure, effectively crashing the DNS server. With a CVSS score of 7.5, the vulnerability is network-exploitable with low attack complexity, requiring no user interaction or privileges, and its primary impact is high availability loss. While there is no known active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ISC | BIND 9 | >= 9.11.33-S1, <= 9.11.37-S1, >= 9.16.13, <= 9.16.50, >= 9.16.13-S1, <= 9.16.50-S1, >= 9.18.0, <= 9.18.27, >= 9.18.11-S1, <= 9.18.27-S1, >= 9.19.0, <= 9.19.24CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024HP ThinPro 8.1 SP4 Security Updates
Oct 29, 2024bind: bind9: Assertion failure when serving both stale cache data and authoritative zone content
Jul 23, 2024Assertion failure when serving both stale cache data and authoritative zone content
Jul 9, 2024Assertion failure when serving both stale cache data and authoritative zone content