named's configured cache size limit can be significantly exceeded
Published Jun 21, 2023
7.5
HIGHCVSS 3.1
EPSS 3.78%
Description
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. When the size of the cache reaches 7/8 of the configured limit, a cache-cleaning algorithm starts to remove expired and/or least-recently used RRsets from the cache, to keep memory use below the configured limit.
It has been discovered that the effectiveness of the cache-cleaning algorithm used in `named` can be severely diminished by querying the resolver for specific RRsets in a certain order, effectively allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.11.0 through 9.16.41, 9.18.0 through 9.18.15, 9.19.0 through 9.19.13, 9.11.3-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.
Affected products
-
- Version 9.11.0StatusaffectedConstraints<=9.16.41
- Version 9.11.3-S1StatusaffectedConstraints<=9.16.41-S1
- Version 9.18.0StatusaffectedConstraints<=9.18.15
- Version 9.18.11-S1StatusaffectedConstraints<=9.18.15-S1
- Version 9.19.0StatusaffectedConstraints<=9.19.13
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 10.0
- 11.0
- 12.0
Configuration 3
- 37
- 38
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
No data.
Red Hat Enterprise Linux 7
bind-32:9.11.4-26.P2.el7_9.14
Fixed · RHSA-2023:4152
Red Hat Enterprise Linux 8
bind-32:9.11.36-8.el8_8.1
Fixed · RHSA-2023:4102
Red Hat Enterprise Linux 8
bind-32:9.11.36-8.el8_8.1
Fixed · RHSA-2023:4102
Red Hat Enterprise Linux 8
bind9.16-32:9.16.23-0.14.el8_8.1
Fixed · RHSA-2023:4100
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
bind-32:9.11.4-26.P2.el8_1.7
Fixed · RHSA-2023:4154
Red Hat Enterprise Linux 8.2 Advanced Update Support
bind-32:9.11.13-6.el8_2.5
Fixed · RHSA-2023:4153
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
bind-32:9.11.13-6.el8_2.5
Fixed · RHSA-2023:4153
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
bind-32:9.11.13-6.el8_2.5
Fixed · RHSA-2023:4153
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
bind-32:9.11.26-4.el8_4.2
Fixed · RHSA-2023:4332
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
bind-32:9.11.26-4.el8_4.2
Fixed · RHSA-2023:4332
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
bind-32:9.11.26-4.el8_4.2
Fixed · RHSA-2023:4332
Red Hat Enterprise Linux 8.6 Extended Update Support
bind-32:9.11.36-3.el8_6.4
Fixed · RHSA-2023:4101
Red Hat Enterprise Linux 8.6 Extended Update Support
bind9.16-32:9.16.23-0.7.el8_6.2
Fixed · RHSA-2023:4037
Red Hat Enterprise Linux 9
bind-32:9.16.23-11.el9_2.1
Fixed · RHSA-2023:4099
Red Hat Enterprise Linux 9.0 Extended Update Support
bind-32:9.16.23-1.el9_0.2
Fixed · RHSA-2023:4005
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 9
dhcp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | bind-32:9.11.4-26.P2.el7_9.14 | Fixed | RHSA-2023:4152 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-8.el8_8.1 | Fixed | RHSA-2023:4102 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-8.el8_8.1 | Fixed | RHSA-2023:4102 |
| Red Hat Enterprise Linux 8 | bind9.16-32:9.16.23-0.14.el8_8.1 | Fixed | RHSA-2023:4100 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | bind-32:9.11.4-26.P2.el8_1.7 | Fixed | RHSA-2023:4154 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | bind-32:9.11.13-6.el8_2.5 | Fixed | RHSA-2023:4153 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | bind-32:9.11.13-6.el8_2.5 | Fixed | RHSA-2023:4153 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | bind-32:9.11.13-6.el8_2.5 | Fixed | RHSA-2023:4153 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | bind-32:9.11.26-4.el8_4.2 | Fixed | RHSA-2023:4332 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | bind-32:9.11.26-4.el8_4.2 | Fixed | RHSA-2023:4332 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | bind-32:9.11.26-4.el8_4.2 | Fixed | RHSA-2023:4332 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | bind-32:9.11.36-3.el8_6.4 | Fixed | RHSA-2023:4101 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | bind9.16-32:9.16.23-0.7.el8_6.2 | Fixed | RHSA-2023:4037 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-11.el9_2.1 | Fixed | RHSA-2023:4099 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | bind-32:9.16.23-1.el9_0.2 | Fixed | RHSA-2023:4005 |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.42, 9.18.16, 9.19.14, 9.16.42-S1, or 9.18.16-S1.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Dec 6, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.78% (0.03776) | 89.60th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.39% (0.03386) | 87.20th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.87% (0.00869) | 74.46th | v4 (v2025.03.14) |
| Nov 18, 2025 | 14.41% (0.14406) | 93.80th | v4 (v2025.03.14) |
| Apr 15, 2025 | 0.56% (0.00558) | 66.82th | v4 (v2025.03.14) |
| Mar 30, 2025 | 11.14% (0.11139) | 92.85th | v4 (v2025.03.14) |
| Mar 29, 2025 | 25.78% (0.25778) | 93.95th | v4 (v2025.03.14) |
| Mar 28, 2025 | 11.14% (0.11139) | 92.85th | v4 (v2025.03.14) |
| Mar 27, 2025 | 25.78% (0.25778) | 95.51th | v4 (v2025.03.14) |
| Mar 25, 2025 | 11.14% (0.11139) | 92.79th | v4 (v2025.03.14) |
| Mar 24, 2025 | 25.78% (0.25778) | 95.77th | v4 (v2025.03.14) |
| Mar 23, 2025 | 1.19% (0.01185) | 74.48th | v4 (v2025.03.14) |
| Mar 20, 2025 | 11.14% (0.11139) | 92.93th | v4 (v2025.03.14) |
| Mar 19, 2025 | 1.19% (0.01185) | 76.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 11.14% (0.11139) | 92.94th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.20% (0.00199) | 58.80th | v3 (v2023.03.01) |
| Jun 27, 2024 | 0.13% (0.00127) | 47.75th | v3 (v2023.03.01) |
| Jul 20, 2023 | 0.08% (0.00081) | 33.54th | v3 (v2023.03.01) |
| Jul 4, 2023 | 0.07% (0.00073) | 30.27th | v3 (v2023.03.01) |
| Jun 25, 2023 | 0.05% (0.00049) | 16.24th | v3 (v2023.03.01) |
| Jun 22, 2023 | 0.05% (0.00046) | 13.97th | v3 (v2023.03.01) |
References (11)
- http://www.openwall.com/lists/oss-security/2023/06/21/6 Mailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-2828 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2216227 Issue Tracking
- https://kb.isc.org/docs/cve-2023-2828 vendor-advisoryVendor Advisory
- https://lists.debian.org/debian-lts-announce/2023/07/msg00021.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEFCEVCTYEMKTWA7V7EYPI5YQQ4JWDLI/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3K6AJK7RRSR53HRF5GGKPA6PDUDWOD2/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-2828
- https://security.netapp.com/advisory/ntap-20230703-0010/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-2828
- https://www.debian.org/security/2023/dsa-5439 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2023/06/21/6 | Mailing ListPatchThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-2828 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2216227 | Issue Tracking | |
| https://kb.isc.org/docs/cve-2023-2828 | vendor-advisoryVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/07/msg00021.html | Mailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEFCEVCTYEMKTWA7V7EYPI5YQQ4JWDLI/ | Mailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U3K6AJK7RRSR53HRF5GGKPA6PDUDWOD2/ | Mailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-2828 | ||
| https://security.netapp.com/advisory/ntap-20230703-0010/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-2828 | ||
| https://www.debian.org/security/2023/dsa-5439 | Third Party Advisory |
Change history (0)
No recorded changes yet.