A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly
Published Sep 20, 2023
7.5
HIGHCVSS 3.1
EPSS 2.85%
Description
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key; only network access to the control channel's configured TCP port is necessary. This issue affects BIND 9 versions 9.2.0 through 9.16.43, 9.18.0 through 9.18.18, 9.19.0 through 9.19.16, 9.9.3-S1 through 9.16.43-S1, and 9.18.0-S1 through 9.18.18-S1.
Affected products
-
- Version 9.18.0StatusaffectedConstraints<=9.18.18
- Version 9.18.0-S1StatusaffectedConstraints<=9.18.18-S1
- Version 9.19.0StatusaffectedConstraints<=9.19.16
- Version 9.2.0StatusaffectedConstraints<=9.16.43
- Version 9.9.3-S1StatusaffectedConstraints<=9.16.43-S1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
- ≥ 9.2.0 · < 9.16.44
- ≥ 9.18.0 · < 9.18.19
- ≥ 9.19.0 · < 9.19.17
- 9.9.3
- 9.9.12
- 9.9.13
- 9.10.5
- 9.10.7
- 9.11.3
- 9.11.3
- 9.11.4
- 9.11.5
- 9.11.5
- 9.11.5
- 9.11.6
- 9.11.7
- 9.11.8
- 9.11.12
- 9.11.21
- 9.11.27
- 9.11.29
- 9.11.35
- 9.11.37
- 9.16.8
- 9.16.11
- 9.16.12
- 9.16.13
- 9.16.14
- 9.16.21
- 9.16.32
- 9.16.36
- 9.16.43
- 9.18.0
- 9.18.18
Configuration 2
- 37
- 38
Configuration 3
- 10.0
- 11.0
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
bind-32:9.8.2-0.68.rc1.el6_10.14
Fixed · RHSA-2025:0039
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
bind-dyndb-ldap-0:2.3-8.el6_10.1
Fixed · RHSA-2025:0039
Red Hat Enterprise Linux 7
bind-32:9.11.4-26.P2.el7_9.15
Fixed · RHSA-2023:5691
Red Hat Enterprise Linux 8
bind-32:9.11.36-8.el8_8.2
Fixed · RHSA-2023:5474
Red Hat Enterprise Linux 8
bind-32:9.11.36-8.el8_8.2
Fixed · RHSA-2023:5474
Red Hat Enterprise Linux 8
bind9.16-32:9.16.23-0.14.el8_8.2
Fixed · RHSA-2023:5460
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
bind-32:9.11.4-26.P2.el8_1.8
Fixed · RHSA-2023:5526
Red Hat Enterprise Linux 8.2 Advanced Update Support
bind-32:9.11.13-6.el8_2.6
Fixed · RHSA-2023:5527
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
bind-32:9.11.13-6.el8_2.6
Fixed · RHSA-2023:5527
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
bind-32:9.11.13-6.el8_2.6
Fixed · RHSA-2023:5527
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
bind-32:9.11.26-4.el8_4.3
Fixed · RHSA-2023:5529
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
bind-32:9.11.26-4.el8_4.3
Fixed · RHSA-2023:5529
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
bind-32:9.11.26-4.el8_4.3
Fixed · RHSA-2023:5529
Red Hat Enterprise Linux 8.6 Extended Update Support
bind-32:9.11.36-3.el8_6.5
Fixed · RHSA-2023:5473
Red Hat Enterprise Linux 8.6 Extended Update Support
bind9.16-32:9.16.23-0.7.el8_6.3
Fixed · RHSA-2023:5771
Red Hat Enterprise Linux 9
bind-32:9.16.23-11.el9_2.2
Fixed · RHSA-2023:5689
Red Hat Enterprise Linux 9.0 Extended Update Support
bind-32:9.16.23-1.el9_0.3
Fixed · RHSA-2023:5690
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | bind-32:9.8.2-0.68.rc1.el6_10.14 | Fixed | RHSA-2025:0039 |
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | bind-dyndb-ldap-0:2.3-8.el6_10.1 | Fixed | RHSA-2025:0039 |
| Red Hat Enterprise Linux 7 | bind-32:9.11.4-26.P2.el7_9.15 | Fixed | RHSA-2023:5691 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-8.el8_8.2 | Fixed | RHSA-2023:5474 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-8.el8_8.2 | Fixed | RHSA-2023:5474 |
| Red Hat Enterprise Linux 8 | bind9.16-32:9.16.23-0.14.el8_8.2 | Fixed | RHSA-2023:5460 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | bind-32:9.11.4-26.P2.el8_1.8 | Fixed | RHSA-2023:5526 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | bind-32:9.11.13-6.el8_2.6 | Fixed | RHSA-2023:5527 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | bind-32:9.11.13-6.el8_2.6 | Fixed | RHSA-2023:5527 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | bind-32:9.11.13-6.el8_2.6 | Fixed | RHSA-2023:5527 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | bind-32:9.11.26-4.el8_4.3 | Fixed | RHSA-2023:5529 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | bind-32:9.11.26-4.el8_4.3 | Fixed | RHSA-2023:5529 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | bind-32:9.11.26-4.el8_4.3 | Fixed | RHSA-2023:5529 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | bind-32:9.11.36-3.el8_6.5 | Fixed | RHSA-2023:5473 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | bind9.16-32:9.16.23-0.7.el8_6.3 | Fixed | RHSA-2023:5771 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-11.el9_2.2 | Fixed | RHSA-2023:5689 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | bind-32:9.16.23-1.el9_0.3 | Fixed | RHSA-2023:5690 |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.44, 9.18.19, 9.19.17, 9.16.44-S1, or 9.18.19-S1.
Red Hat statement
Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key, only network access to the control channel’s configured TCP port is necessary.
Red Hat mitigation
By default, named only allows control-channel connections over the loopback interface, making this attack impossible to carry out over the network. When enabling remote access to the control channel’s configured TCP port, care should be taken to limit such access to trusted IP ranges on the network level, effectively preventing unauthorized parties from carrying out the attack described in this advisory.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jun 3, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.85% (0.02854) | 86.24th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.63% (0.02626) | 83.45th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.29% (0.00287) | 51.78th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.33% (0.02328) | 83.48th | v4 (v2025.03.14) |
| Mar 21, 2025 | 0.16% (0.00160) | 33.77th | v4 (v2025.03.14) |
| Mar 17, 2025 | 1.49% (0.01486) | 79.74th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.25% (0.00248) | 65.30th | v3 (v2023.03.01) |
| Feb 17, 2024 | 0.15% (0.00154) | 50.56th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.33% (0.00329) | 70.15th | v3 (v2023.03.01) |
| Nov 4, 2023 | 0.29% (0.00289) | 65.55th | v3 (v2023.03.01) |
| Oct 14, 2023 | 0.11% (0.00110) | 43.68th | v3 (v2023.03.01) |
| Sep 23, 2023 | 0.05% (0.00050) | 17.01th | v3 (v2023.03.01) |
| Sep 22, 2023 | 0.04% (0.00044) | 10.59th | v3 (v2023.03.01) |
References (12)
- http://www.openwall.com/lists/oss-security/2023/09/20/2 Mailing ListPatch
- https://access.redhat.com/security/cve/CVE-2023-3341 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2239621 Issue Tracking
- https://kb.isc.org/docs/cve-2023-3341 vendor-advisoryVendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00021.html Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IPJLLTJCSDJJII7IIZPLTBQNWP7MZH7F/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/U35OARLQCPMVCBBPHWBXY5M6XJLD2TZ5/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSK5V4W4OHPM3JTJGWAQD6CZW7SFD75B/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3341
- https://security.netapp.com/advisory/ntap-20231013-0003/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-3341
- https://www.debian.org/security/2023/dsa-5504 Third Party Advisory
Change history (0)
No recorded changes yet.