{
  "threat_severity" : "Important",
  "public_date" : "2024-07-23T00:00:00Z",
  "bugzilla" : {
    "description" : "bind: bind9: Assertion failure when serving both stale cache data and authoritative zone content",
    "id" : "2298904",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2298904"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
    "status" : "verified"
  },
  "details" : [ "Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure.\nThis issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.", "A flaw was found in the bind9 package, where a client query triggers stale data and also requires local lookups may trigger a assertion failure. This issue results in a denial of service of the bind server." ],
  "statement" : "The discovered flaw in the BIND9 package is of high severity due to its dual impact on DNS server functionality and stability. The issue where client queries trigger the return of stale data undermines the integrity and reliability of DNS responses, potentially leading to incorrect or outdated information being served to clients. This can cause significant disruptions in services reliant on accurate DNS resolutions. Moreover, the assertion failure triggered by local lookups poses a critical threat, as it can crash the BIND server, resulting in a denial of service (DoS). Such an outage disrupts DNS operations, impacting network availability and access to internet services.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2024-08-14T00:00:00Z",
    "advisory" : "RHSA-2024:5390",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "bind9.16-32:9.16.23-0.22.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support",
    "release_date" : "2024-08-15T00:00:00Z",
    "advisory" : "RHSA-2024:5418",
    "cpe" : "cpe:/a:redhat:rhel_aus:8.6",
    "package" : "bind9.16-32:9.16.23-0.7.el8_6.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Telecommunications Update Service",
    "release_date" : "2024-08-15T00:00:00Z",
    "advisory" : "RHSA-2024:5418",
    "cpe" : "cpe:/a:redhat:rhel_tus:8.6",
    "package" : "bind9.16-32:9.16.23-0.7.el8_6.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions",
    "release_date" : "2024-08-15T00:00:00Z",
    "advisory" : "RHSA-2024:5418",
    "cpe" : "cpe:/a:redhat:rhel_e4s:8.6",
    "package" : "bind9.16-32:9.16.23-0.7.el8_6.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8.8 Extended Update Support",
    "release_date" : "2024-08-19T00:00:00Z",
    "advisory" : "RHSA-2024:5525",
    "cpe" : "cpe:/a:redhat:rhel_eus:8.8",
    "package" : "bind9.16-32:9.16.23-0.14.el8_8.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2024-08-15T00:00:00Z",
    "advisory" : "RHSA-2024:5231",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "bind-32:9.16.23-18.el9_4.6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2024-08-15T00:00:00Z",
    "advisory" : "RHSA-2024:5231",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "bind-dyndb-ldap-0:11.9-10.el9_4"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2024-08-27T00:00:00Z",
    "advisory" : "RHSA-2024:5907",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "bind-32:9.16.23-1.el9_0.7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions",
    "release_date" : "2024-08-27T00:00:00Z",
    "advisory" : "RHSA-2024:5907",
    "cpe" : "cpe:/a:redhat:rhel_e4s:9.0",
    "package" : "bind-dyndb-ldap-0:11.9-7.el9_0.3"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Extended Update Support",
    "release_date" : "2024-08-26T00:00:00Z",
    "advisory" : "RHSA-2024:5813",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.2",
    "package" : "bind-32:9.16.23-11.el9_2.5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9.2 Extended Update Support",
    "release_date" : "2024-08-26T00:00:00Z",
    "advisory" : "RHSA-2024:5813",
    "cpe" : "cpe:/a:redhat:rhel_eus:9.2",
    "package" : "bind-dyndb-ldap-0:11.9-8.el9_2.3"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.13",
    "release_date" : "2024-09-04T00:00:00Z",
    "advisory" : "RHSA-2024:6009",
    "cpe" : "cpe:/a:redhat:openshift:4.13::el9",
    "package" : "rhcos-413.92.202408270922-0"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.14",
    "release_date" : "2024-09-11T00:00:00Z",
    "advisory" : "RHSA-2024:6406",
    "cpe" : "cpe:/a:redhat:openshift:4.14::el9",
    "package" : "rhcos-414.92.202409041930-0"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.15",
    "release_date" : "2024-09-05T00:00:00Z",
    "advisory" : "RHSA-2024:6013",
    "cpe" : "cpe:/a:redhat:openshift:4.15::el9",
    "package" : "rhcos-415.92.202408271217-0"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4.16",
    "release_date" : "2024-09-03T00:00:00Z",
    "advisory" : "RHSA-2024:6004",
    "cpe" : "cpe:/a:redhat:openshift:4.16::el9",
    "package" : "rhcos-416.94.202408260940-0"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "bind",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "bind",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "bind",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "bind",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "bind9.18",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "dhcp",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-4076\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-4076" ],
  "name" : "CVE-2024-4076",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}