[El-errata] ELSA-2024-1781 Important: Oracle Linux 8 bind9.16 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Apr 15 14:03:54 UTC 2024


Oracle Linux Security Advisory ELSA-2024-1781

http://linux.oracle.com/errata/ELSA-2024-1781.html

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

x86_64:
bind9.16-9.16.23-0.16.el8_9.2.x86_64.rpm
bind9.16-chroot-9.16.23-0.16.el8_9.2.x86_64.rpm
bind9.16-dnssec-utils-9.16.23-0.16.el8_9.2.x86_64.rpm
bind9.16-libs-9.16.23-0.16.el8_9.2.x86_64.rpm
bind9.16-license-9.16.23-0.16.el8_9.2.noarch.rpm
bind9.16-utils-9.16.23-0.16.el8_9.2.x86_64.rpm
python3-bind9.16-9.16.23-0.16.el8_9.2.noarch.rpm
bind9.16-devel-9.16.23-0.16.el8_9.2.i686.rpm
bind9.16-devel-9.16.23-0.16.el8_9.2.x86_64.rpm
bind9.16-doc-9.16.23-0.16.el8_9.2.noarch.rpm
bind9.16-libs-9.16.23-0.16.el8_9.2.i686.rpm

aarch64:
bind9.16-9.16.23-0.16.el8_9.2.aarch64.rpm
bind9.16-chroot-9.16.23-0.16.el8_9.2.aarch64.rpm
bind9.16-dnssec-utils-9.16.23-0.16.el8_9.2.aarch64.rpm
bind9.16-libs-9.16.23-0.16.el8_9.2.aarch64.rpm
bind9.16-license-9.16.23-0.16.el8_9.2.noarch.rpm
bind9.16-utils-9.16.23-0.16.el8_9.2.aarch64.rpm
python3-bind9.16-9.16.23-0.16.el8_9.2.noarch.rpm
bind9.16-devel-9.16.23-0.16.el8_9.2.aarch64.rpm
bind9.16-doc-9.16.23-0.16.el8_9.2.noarch.rpm


SRPMS:
http://oss.oracle.com/ol8/SRPMS-updates//bind9.16-9.16.23-0.16.el8_9.2.src.rpm

Related CVEs:

CVE-2023-4408
CVE-2023-5517
CVE-2023-5679
CVE-2023-6516
CVE-2023-50387
CVE-2023-50868




Description of changes:

[32:9.16.23-0.16.2]
- Prevent crashing at masterformat system test (CVE-2023-6516)

[32:9.16.23-0.16.1]
- Prevent increased CPU load on large DNS messages (CVE-2023-4408)
- Prevent assertion failure when nxdomain-redirect is used with
 RFC 1918 reverse zones (CVE-2023-5517)
- Prevent assertion failure if DNS64 and serve-stale is used (CVE-2023-5679)
- Specific recursive query patterns may lead to an out-of-memory
  condition (CVE-2023-6516)
- Prevent increased CPU consumption in DNSSEC validator (CVE-2023-50387
  CVE-2023-50868)
- Import tests for large DNS messages fix
- Add downstream change complementing CVE-2023-50387

[32:9.16.23-0.16]
- Limit the amount of recursion possible in control channel (CVE-2023-3341)

[32:9.16.23-0.15]
- Strengten cache cleaning to prevent overflowing configured limit
  (CVE-2023-2828)




More information about the El-errata mailing list