suse · CVE-2023-2829

Quick triage

Priority: high Published: 2023-06-22 23:18:28 UTC Updated: 2025-04-07 23:32:35 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-2829 severity important: SUSE including 32 source package names (bind, bind-chrootenv, …), 369 product×package rows across 38 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 7, … (38 product lines)): Known Not Affected 369.

Description:

A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1.

cvelogic Threat Intelligence