Limiting simultaneous TCP clients was ineffective
Published Oct 9, 2019
7.5
HIGHCVSS 3.1
EPSS 6.46%
Description
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow the number of simultaneous connections beyond this limit. Versions affected: BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.
Affected products
-
- Version BIND 9.9.0 -> 9.10.8-P1, 9.11.0 -> 9.11.6, 9.12.0 -> 9.12.4, 9.14.0. BIND 9 Supported Preview Edition versions 9.9.3-S1 -> 9.11.5-S3, and 9.11.5-S5. Versions 9.13.0 -> 9.13.7 of the 9.13 development branch are also affected. Versions prior to BIND 9.9.0 have not been evaluated for vulnerability to CVE-2018-5743.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| ISC | BIND 9 | n/a |
|
Configuration 1
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 2
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 3
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 4
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 5
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 6
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.1
- 15.0.0
Configuration 7
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 8
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 9
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 10
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.0.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 11
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 12
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
Configuration 13
- ≥ 9.9.0 · ≤ 9.10.8
- ≥ 9.11.0 · ≤ 9.11.6
- ≥ 9.12.0 · ≤ 9.12.4
- ≥ 9.13.0 · ≤ 9.13.7
- 9.9.3
- 9.10.8
- 9.11.5
- 9.11.5
- 9.14.0
Configuration 14
- 3.1.1
Configuration 15
- ≥ 5.0.0 · ≤ 5.4.0
- ≥ 6.0.0 · ≤ 6.1.0
Configuration 17
- ≥ 11.5.2 · ≤ 11.6.5
- ≥ 12.1.0 · ≤ 12.1.4
- ≥ 13.1.0 · ≤ 13.1.1
- ≥ 14.0.0 · ≤ 14.1.0
- 15.0.0
No data.
Red Hat Enterprise Linux 6
bind-32:9.8.2-0.68.rc1.el6_10.3
Fixed · RHSA-2019:1492
Red Hat Enterprise Linux 7
bind-32:9.9.4-74.el7_6.1
Fixed · RHSA-2019:1294
Red Hat Enterprise Linux 7.4 Extended Update Support
bind-32:9.9.4-51.el7_4.3
Fixed · RHSA-2019:2698
Red Hat Enterprise Linux 7.5 Extended Update Support
bind-32:9.9.4-61.el7_5.2
Fixed · RHSA-2019:2977
Red Hat Enterprise Linux 8
bind-32:9.11.4-17.P2.el8_0
Fixed · RHSA-2019:1145
Red Hat Enterprise Linux 8
bind-32:9.11.4-17.P2.el8_0
Fixed · RHSA-2019:1145
Red Hat Enterprise Linux 5
bind
Out of support scope
Red Hat Enterprise Linux 5
bind97
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | bind-32:9.8.2-0.68.rc1.el6_10.3 | Fixed | RHSA-2019:1492 |
| Red Hat Enterprise Linux 7 | bind-32:9.9.4-74.el7_6.1 | Fixed | RHSA-2019:1294 |
| Red Hat Enterprise Linux 7.4 Extended Update Support | bind-32:9.9.4-51.el7_4.3 | Fixed | RHSA-2019:2698 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | bind-32:9.9.4-61.el7_5.2 | Fixed | RHSA-2019:2977 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.4-17.P2.el8_0 | Fixed | RHSA-2019:1145 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.4-17.P2.el8_0 | Fixed | RHSA-2019:1145 |
| Red Hat Enterprise Linux 5 | bind | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to a version of BIND containing a fix for the ineffective limits.
+ BIND 9.11.6-P1 + BIND 9.12.4-P1 + BIND 9.14.1
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
+ BIND 9.11.5-S6 + BIND 9.11.6-S1
Red Hat statement
This bind flaw can be exploited by a remote attacker (AV:N) by opening large number of simultaneous TCP client connections with the server. No special exploit code is required apart from the ability to open large number of TCP connections simultaneously either from one attacker machine or via some distributed attacker network (AC:L and PR:L). No user interaction is required from the server side (UI:N). The attacker can cause denial of service (A:H) by exhausting the file descriptor pool which named has access to. Also in cases where named process is not limited by OS-enforced per-process limits, this could cause exhaustion of available free file descriptors on the system running the named server causing denial of service for other processes running on that machine (S:C).
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.46% (0.06457) | 93.52th | v5 (v2026.06.15) |
| Jun 23, 2026 | 6.40% (0.06404) | 92.78th | v5 (v2026.06.15) |
| Jun 15, 2026 | 11.56% (0.11561) | 95.47th | v5 (v2026.06.15) |
| Mar 3, 2026 | 5.69% (0.05693) | 90.30th | v4 (v2025.03.14) |
| Nov 21, 2025 | 1.77% (0.01766) | 82.06th | v4 (v2025.03.14) |
| Nov 18, 2025 | 4.65% (0.04649) | 88.22th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.96% (0.01956) | 81.85th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.19% (0.06194) | 84.34th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.96% (0.01956) | 82.27th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.23% (0.00232) | 61.70th | v3 (v2023.03.01) |
| Apr 17, 2024 | 0.23% (0.00232) | 60.91th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.20% (0.00202) | 57.93th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00184) | 53.93th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Sep 2, 2022 | 0.95% (0.00954) | 34.50th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.95% (0.00954) | 16.28th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.83% (0.00833) | 24.58th | v1 |
| Jan 6, 2022 | 0.83% (0.00833) | 23.96th | v1 |
| Sep 1, 2021 | 0.83% (0.00833) | 57.50th | v1 |
| Apr 14, 2021 | 0.83% (0.00833) | 0.00th | v1 |
References (7)
- https://access.redhat.com/security/cve/CVE-2018-5743 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1702541 Issue Tracking
- https://kb.isc.org/docs/cve-2018-5743 x_refsource_CONFIRMThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-5743
- https://support.f5.com/csp/article/K74009656?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2018-5743
- https://www.synology.com/security/advisory/Synology_SA_19_20 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-5743 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1702541 | Issue Tracking | |
| https://kb.isc.org/docs/cve-2018-5743 | x_refsource_CONFIRMThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-5743 | ||
| https://support.f5.com/csp/article/K74009656?utm_source=f5support&%3Butm_medium=RSS | x_refsource_CONFIRM | |
| https://www.cve.org/CVERecord?id=CVE-2018-5743 | ||
| https://www.synology.com/security/advisory/Synology_SA_19_20 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.