A flood of DNS messages over TCP may make the server unstable
Published Jul 23, 2024
7.5
HIGHCVSS 3.1
EPSS 4.68%
Description
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.
Affected products
-
- Version 9.18.1StatusaffectedConstraints<=9.18.27
- Version 9.18.11-S1StatusaffectedConstraints<=9.18.27-S1
- Version 9.19.0StatusaffectedConstraints<=9.19.24
- Version
No data.
-
- Version 9.18.1StatusaffectedConstraints<=9.18.27
- Version 9.18.11-s1StatusaffectedConstraints<=9.18.27-s1
- Version 9.19.0StatusaffectedConstraints<=9.19.24
- Version
Red Hat Enterprise Linux 10
bind
Not affected
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 8
bind9.16
Not affected
Red Hat Enterprise Linux 9
bind
Not affected
Red Hat Enterprise Linux 9
dhcp
Not affected
Red Hat OpenShift Container Platform 4
rhcos
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind9.16 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | rhcos | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.28, 9.20.0, or 9.18.28-S1.
Red Hat statement
This vulnerability does not affect the bind and dhcp versions as shipped with Red Hat Enterprise Linux 6, 7, 8 and 9. The bind versions vulnerable to this flaw are 9.18.1 to 9.18.27 and 9.19.0 to 9.19.24, while the most recent bind version in Red Hat Enterprise Linux 9 is bind-9.16.26-11.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jul 23, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (26 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 4.68% (0.04680) | 91.49th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.68% (0.04680) | 90.57th | v5 (v2026.06.15) |
| May 3, 2026 | 16.69% (0.16690) | 94.95th | v4 (v2025.03.14) |
| Apr 19, 2026 | 15.62% (0.15622) | 94.71th | v4 (v2025.03.14) |
| Dec 18, 2025 | 16.69% (0.16690) | 94.71th | v4 (v2025.03.14) |
| Dec 12, 2025 | 15.62% (0.15622) | 94.45th | v4 (v2025.03.14) |
| Nov 24, 2025 | 12.13% (0.12128) | 93.53th | v4 (v2025.03.14) |
| Nov 22, 2025 | 9.36% (0.09358) | 92.44th | v4 (v2025.03.14) |
| Nov 21, 2025 | 13.00% (0.13003) | 93.80th | v4 (v2025.03.14) |
| Nov 18, 2025 | 55.96% (0.55959) | 98.01th | v4 (v2025.03.14) |
| Oct 27, 2025 | 13.00% (0.13003) | 93.81th | v4 (v2025.03.14) |
| Oct 25, 2025 | 10.06% (0.10062) | 92.73th | v4 (v2025.03.14) |
| Sep 4, 2025 | 13.00% (0.13003) | 93.83th | v4 (v2025.03.14) |
| Aug 31, 2025 | 14.76% (0.14757) | 94.24th | v4 (v2025.03.14) |
| May 31, 2025 | 35.84% (0.35843) | 96.88th | v4 (v2025.03.14) |
| May 19, 2025 | 29.73% (0.29733) | 96.36th | v4 (v2025.03.14) |
| Apr 18, 2025 | 28.67% (0.28673) | 96.20th | v4 (v2025.03.14) |
| Apr 15, 2025 | 26.69% (0.26691) | 95.99th | v4 (v2025.03.14) |
| Apr 8, 2025 | 46.10% (0.46101) | 97.39th | v4 (v2025.03.14) |
| Mar 28, 2025 | 43.53% (0.43525) | 97.24th | v4 (v2025.03.14) |
| Mar 26, 2025 | 54.55% (0.54547) | 97.81th | v4 (v2025.03.14) |
| Mar 23, 2025 | 43.53% (0.43525) | 97.12th | v4 (v2025.03.14) |
| Mar 20, 2025 | 10.39% (0.10393) | 92.58th | v4 (v2025.03.14) |
| Mar 17, 2025 | 43.53% (0.43525) | 97.21th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00049) | 20.77th | v3 (v2023.03.01) |
| Jul 24, 2024 | 0.05% (0.00046) | 17.45th | v3 (v2023.03.01) |
References (8)
- http://www.openwall.com/lists/oss-security/2024/07/23/1
- http://www.openwall.com/lists/oss-security/2024/07/31/2
- https://access.redhat.com/security/cve/CVE-2024-0760 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2298878 Issue Tracking
- https://kb.isc.org/docs/cve-2024-0760 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-0760
- https://security.netapp.com/advisory/ntap-20240731-0004/
- https://www.cve.org/CVERecord?id=CVE-2024-0760
Change history (0)
No recorded changes yet.