ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 취약점
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21...
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21...
영향 제품·버전
제품 ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8
영향 버전 ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 >= 9.11.0 <= 9.16.50, >= 9.18.0 <= 9.18.48, >= 9.20.0 <= 9.20.22, >= 9.21.0 <= 9.21.21, >= 9.11.3-S1 <= 9.16.50-S1, >= 9.18.11-S1 <= 9.18.48-S1, >= 9.20.9-S1 <= 9.20.22-S1, >= 9.18.0 < 9.18.49, >= 9.20.0 < 9.20.23, >= 9.21.0 < 9.21.22
수정 버전 ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 9.18.49, 9.20.23, 9.21.22
ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8의 현재 전체 버전이 공식 영향 범위(ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 >= 9.11.0 <= 9.16.50, >= 9.18.0 <= 9.18.48, >= 9.20.0 <= 9.20.22, >= 9.21.0 <= 9.21.21, >= 9.11.3-S1 <= 9.16.50-S1, >= 9.18.11-S1 <= 9.18.48-S1, >= 9.20.9-S1 <= 9.20.22-S1, >= 9.18.0 < 9.18.49, >= 9.20.0 < 9.20.23, >= 9.21.0 < 9.21.22)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
공식 보안 권고 원문에서 현재 제품·에디션·설치 방식이 9.18.49, 9.20.23, 9.21.22 기준의 대상인지 확인한 뒤 공급사 절차로 적용합니다.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 ISC BIND 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 9.18.49, 9.20.23, 9.21.22 기준을 충족하는지 확인합니다. 이어서 메모리 손상 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.