Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name.
This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-5734-1 bind9 security update
EUVD EUVD EUVD-2024-17464 Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.4-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.
Ubuntu USN Ubuntu USN USN-6909-1 Bind vulnerabilities
Ubuntu USN Ubuntu USN USN-6909-2 Bind vulnerabilities
Ubuntu USN Ubuntu USN USN-6909-3 Bind vulnerabilities
Fixes

Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.28, 9.20.0, or 9.18.28-S1.


Workaround

No workarounds known.

History

Mon, 14 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00684}

epss

{'score': 0.00899}


Fri, 14 Feb 2025 03:15:00 +0900

Type Values Removed Values Added
First Time appeared Isc
Isc bind
CPEs cpe:2.3:a:isc:bind:9.11.0:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.11.4:s1:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.16.0:*:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.16.8:s1:*:*:*:*:*:*
cpe:2.3:a:isc:bind:9.18.0:*:*:*:-:*:*:*
cpe:2.3:a:isc:bind:9.18.11:s1:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.19.0:*:*:*:-:*:*:*
Vendors & Products Isc
Isc bind
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 23:45:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.12::el8

Thu, 12 Sep 2024 11:30:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.14::el9

Fri, 06 Sep 2024 22:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat openshift
CPEs cpe:/a:redhat:openshift:4.13::el9
cpe:/a:redhat:openshift:4.15::el9
cpe:/a:redhat:openshift:4.16::el9
Vendors & Products Redhat openshift

Thu, 29 Aug 2024 04:00:00 +0900

Type Values Removed Values Added
First Time appeared Redhat rhel Els
CPEs cpe:/o:redhat:rhel_els:7
Vendors & Products Redhat rhel Els

Wed, 28 Aug 2024 15:15:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_e4s:9.0

Wed, 28 Aug 2024 04:00:00 +0900

Type Values Removed Values Added
CPEs cpe:/o:redhat:rhel_aus:7.7

Tue, 27 Aug 2024 15:15:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_aus:8.4
cpe:/a:redhat:rhel_e4s:8.4
cpe:/a:redhat:rhel_tus:8.4

Tue, 27 Aug 2024 04:00:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_eus:9.2

Wed, 21 Aug 2024 15:30:00 +0900

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_aus:8.2

Tue, 20 Aug 2024 07:30:00 +0900

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:8.8
cpe:/o:redhat:enterprise_linux:8
Vendors & Products Redhat rhel Eus

Sat, 17 Aug 2024 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus
CPEs cpe:/a:redhat:enterprise_linux:8
cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_tus:8.6
Vendors & Products Redhat
Redhat enterprise Linux
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2025-02-13T17:32:25.755Z

Reserved: 2024-02-22T10:11:43.508Z

Link: CVE-2024-1737

cve-icon Vulnrichment

Updated: 2024-08-01T18:48:21.779Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-23T15:15:03.740

Modified: 2024-11-21T08:51:11.837

Link: CVE-2024-1737

cve-icon Redhat

Severity : Important

Publid Date: 2024-07-23T00:00:00Z

Links: CVE-2024-1737 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses