suse · CVE-2023-4236

Quick triage

Priority: high Published: 2023-09-22 23:22:59 UTC Updated: 2026-03-05 03:54:13 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-4236 severity important: SUSE including 49 source package names (bind, bind-9.18.19-1.1, …), 386 product×package rows across 40 product lines (SUSE CaaS Platform 4.0, SUSE Enterprise Storage 7.1, … (40 product lines)): Known Not Affected 369, Fixed 17.

Description:

A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.

cvelogic Threat Intelligence