Specific recursive query patterns may lead to an out-of-memory condition
Published Feb 13, 2024
7.5
HIGHCVSS 3.1
EPSS 1.11%
Description
To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.
Affected products
-
- Version 9.16.0StatusaffectedConstraints<=9.16.45
- Version 9.16.8-S1StatusaffectedConstraints<=9.16.45-S1
- Version
Configuration 1
- ≥ 9.16.0 · ≤ 9.16.45
- 9.16.8
- 9.16.11
- 9.16.12
- 9.16.13
- 9.16.14
- 9.16.21
- 9.16.32
- 9.16.36
- 9.16.43
- 9.16.45
Configuration 2
- n/a
-
- Version 9.16.0StatusaffectedConstraints<=9.16.45
- Version 9.16.8-s1StatusaffectedConstraints<=9.16.45-s1
- Version
Red Hat Enterprise Linux 8
bind9.16-32:9.16.23-0.16.el8_9.2
Fixed · RHSA-2024:1781
Red Hat Enterprise Linux 8.6 Extended Update Support
bind9.16-32:9.16.23-0.7.el8_6.5
Fixed · RHSA-2024:1647
Red Hat Enterprise Linux 8.8 Extended Update Support
bind9.16-32:9.16.23-0.14.el8_8.4
Fixed · RHSA-2024:1648
Red Hat Enterprise Linux 9
bind-32:9.16.23-14.el9_3.4
Fixed · RHSA-2024:1789
Red Hat Enterprise Linux 9
bind-32:9.16.23-18.el9_4.1
Fixed · RHSA-2024:2551
Red Hat Enterprise Linux 9
bind-dyndb-ldap-0:11.9-8.el9_3.3
Fixed · RHSA-2024:1789
Red Hat Enterprise Linux 9
bind-dyndb-ldap-0:11.9-9.el9_4
Fixed · RHSA-2024:2551
Red Hat Enterprise Linux 9.0 Extended Update Support
bind-32:9.16.23-1.el9_0.5
Fixed · RHSA-2024:1800
Red Hat Enterprise Linux 9.0 Extended Update Support
bind-dyndb-ldap-0:11.9-7.el9_0.1
Fixed · RHSA-2024:1800
Red Hat Enterprise Linux 9.2 Extended Update Support
bind-32:9.16.23-11.el9_2.4
Fixed · RHSA-2024:1803
Red Hat Enterprise Linux 9.2 Extended Update Support
bind-dyndb-ldap-0:11.9-8.el9_2.2
Fixed · RHSA-2024:1803
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 9
dhcp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | bind9.16-32:9.16.23-0.16.el8_9.2 | Fixed | RHSA-2024:1781 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | bind9.16-32:9.16.23-0.7.el8_6.5 | Fixed | RHSA-2024:1647 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | bind9.16-32:9.16.23-0.14.el8_8.4 | Fixed | RHSA-2024:1648 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-14.el9_3.4 | Fixed | RHSA-2024:1789 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-18.el9_4.1 | Fixed | RHSA-2024:2551 |
| Red Hat Enterprise Linux 9 | bind-dyndb-ldap-0:11.9-8.el9_3.3 | Fixed | RHSA-2024:1789 |
| Red Hat Enterprise Linux 9 | bind-dyndb-ldap-0:11.9-9.el9_4 | Fixed | RHSA-2024:2551 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | bind-32:9.16.23-1.el9_0.5 | Fixed | RHSA-2024:1800 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | bind-dyndb-ldap-0:11.9-7.el9_0.1 | Fixed | RHSA-2024:1800 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | bind-32:9.16.23-11.el9_2.4 | Fixed | RHSA-2024:1803 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | bind-dyndb-ldap-0:11.9-8.el9_2.2 | Fixed | RHSA-2024:1803 |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.48 or 9.16.48-S1.
Red Hat mitigation
There is no available mitigation for this issue other than applying the required fixes via the released updates.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Feb 20, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.11% (0.01106) | 64.59th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.10% (0.01097) | 61.18th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.63% (0.00628) | 67.81th | v4 (v2025.03.14) |
| Mar 29, 2025 | 2.53% (0.02532) | 75.69th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.63% (0.00628) | 68.48th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.21% (0.00215) | 60.40th | v3 (v2023.03.01) |
| Jul 4, 2024 | 0.11% (0.00108) | 44.07th | v3 (v2023.03.01) |
| May 21, 2024 | 0.05% (0.00052) | 19.70th | v3 (v2023.03.01) |
| Mar 8, 2024 | 0.05% (0.00052) | 17.69th | v3 (v2023.03.01) |
| Feb 21, 2024 | 0.05% (0.00049) | 15.65th | v3 (v2023.03.01) |
| Feb 14, 2024 | 0.05% (0.00046) | 13.59th | v3 (v2023.03.01) |
References (9)
- http://www.openwall.com/lists/oss-security/2024/02/13/1 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-6516 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2263911 Issue Tracking
- https://kb.isc.org/docs/cve-2023-6516 vendor-advisoryVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/ Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/ Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-6516
- https://security.netapp.com/advisory/ntap-20240503-0008/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-6516
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2024/02/13/1 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2023-6516 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2263911 | Issue Tracking | |
| https://kb.isc.org/docs/cve-2023-6516 | vendor-advisoryVendor Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/ | Mailing ListThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/ | Mailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-6516 | ||
| https://security.netapp.com/advisory/ntap-20240503-0008/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-6516 |
Change history (0)
No recorded changes yet.