UBUNTU-CVE-2023-3341

Source
https://ubuntu.com/security/CVE-2023-3341
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-3341.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2023-3341
Upstream
Downstream
Related
Published
2023-09-20T00:00:00Z
Modified
2025-09-08T16:55:46Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

The code that processes control channel messages sent to named calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing named to terminate unexpectedly. Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key; only network access to the control channel's configured TCP port is necessary. This issue affects BIND 9 versions 9.2.0 through 9.16.43, 9.18.0 through 9.18.18, 9.19.0 through 9.19.16, 9.9.3-S1 through 9.16.43-S1, and 9.18.0-S1 through 9.18.18-S1.

References

Affected packages

Ubuntu:20.04:LTS

bind9

Package

Name
bind9
Purl
pkg:deb/ubuntu/bind9@1:9.16.1-0ubuntu2.16?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.16.1-0ubuntu2.16

Affected versions

1:9.*

1:9.11.5.P4+dfsg-5.1ubuntu2
1:9.11.5.P4+dfsg-5.1ubuntu3
1:9.11.5.P4+dfsg-5.1ubuntu4
1:9.11.5.P4+dfsg-5.1ubuntu5
1:9.11.14+dfsg-1ubuntu1
1:9.11.14+dfsg-3ubuntu1
1:9.16.0-1ubuntu3
1:9.16.0-1ubuntu4
1:9.16.0-1ubuntu5
1:9.16.1-0ubuntu1
1:9.16.1-0ubuntu2
1:9.16.1-0ubuntu2.1
1:9.16.1-0ubuntu2.2
1:9.16.1-0ubuntu2.3
1:9.16.1-0ubuntu2.4
1:9.16.1-0ubuntu2.6
1:9.16.1-0ubuntu2.7
1:9.16.1-0ubuntu2.8
1:9.16.1-0ubuntu2.9
1:9.16.1-0ubuntu2.10
1:9.16.1-0ubuntu2.11
1:9.16.1-0ubuntu2.12
1:9.16.1-0ubuntu2.14
1:9.16.1-0ubuntu2.15

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "bind9",
            "binary_version": "1:9.16.1-0ubuntu2.16"
        },
        {
            "binary_name": "bind9-dnsutils",
            "binary_version": "1:9.16.1-0ubuntu2.16"
        },
        {
            "binary_name": "bind9-host",
            "binary_version": "1:9.16.1-0ubuntu2.16"
        },
        {
            "binary_name": "bind9-libs",
            "binary_version": "1:9.16.1-0ubuntu2.16"
        },
        {
            "binary_name": "bind9-utils",
            "binary_version": "1:9.16.1-0ubuntu2.16"
        },
        {
            "binary_name": "bind9utils",
            "binary_version": "1:9.16.1-0ubuntu2.16"
        },
        {
            "binary_name": "dnsutils",
            "binary_version": "1:9.16.1-0ubuntu2.16"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:22.04:LTS

bind9

Package

Name
bind9
Purl
pkg:deb/ubuntu/bind9@1:9.18.12-0ubuntu0.22.04.3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.18.12-0ubuntu0.22.04.3

Affected versions

1:9.*

1:9.16.15-1ubuntu1
1:9.16.15-1ubuntu2
1:9.16.15-1ubuntu3
1:9.18.0-2ubuntu1
1:9.18.0-2ubuntu2
1:9.18.0-2ubuntu3
1:9.18.1-1ubuntu1
1:9.18.1-1ubuntu1.1
1:9.18.1-1ubuntu1.2
1:9.18.1-1ubuntu1.3
1:9.18.12-0ubuntu0.22.04.1
1:9.18.12-0ubuntu0.22.04.2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "bind9",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        },
        {
            "binary_name": "bind9-dev",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        },
        {
            "binary_name": "bind9-dnsutils",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        },
        {
            "binary_name": "bind9-host",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        },
        {
            "binary_name": "bind9-libs",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        },
        {
            "binary_name": "bind9-utils",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        },
        {
            "binary_name": "bind9utils",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        },
        {
            "binary_name": "dnsutils",
            "binary_version": "1:9.18.12-0ubuntu0.22.04.3"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:24.04:LTS

bind9

Package

Name
bind9
Purl
pkg:deb/ubuntu/bind9@1:9.18.18-0ubuntu2?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.18.18-0ubuntu2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "bind9",
            "binary_version": "1:9.18.18-0ubuntu2"
        },
        {
            "binary_name": "bind9-dev",
            "binary_version": "1:9.18.18-0ubuntu2"
        },
        {
            "binary_name": "bind9-dnsutils",
            "binary_version": "1:9.18.18-0ubuntu2"
        },
        {
            "binary_name": "bind9-host",
            "binary_version": "1:9.18.18-0ubuntu2"
        },
        {
            "binary_name": "bind9-libs",
            "binary_version": "1:9.18.18-0ubuntu2"
        },
        {
            "binary_name": "bind9-utils",
            "binary_version": "1:9.18.18-0ubuntu2"
        },
        {
            "binary_name": "bind9utils",
            "binary_version": "1:9.18.18-0ubuntu2"
        },
        {
            "binary_name": "dnsutils",
            "binary_version": "1:9.18.18-0ubuntu2"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:Pro:14.04:LTS

bind9

Package

Name
bind9
Purl
pkg:deb/ubuntu/bind9@1:9.9.5.dfsg-3ubuntu0.19+esm11?arch=source&distro=trusty/esm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.9.5.dfsg-3ubuntu0.19+esm11

Affected versions

1:9.*

1:9.9.3.dfsg.P2-4ubuntu1
1:9.9.3.dfsg.P2-4ubuntu2
1:9.9.3.dfsg.P2-4ubuntu3
1:9.9.5.dfsg-2
1:9.9.5.dfsg-3
1:9.9.5.dfsg-3ubuntu0.1
1:9.9.5.dfsg-3ubuntu0.2
1:9.9.5.dfsg-3ubuntu0.3
1:9.9.5.dfsg-3ubuntu0.4
1:9.9.5.dfsg-3ubuntu0.5
1:9.9.5.dfsg-3ubuntu0.6
1:9.9.5.dfsg-3ubuntu0.7
1:9.9.5.dfsg-3ubuntu0.8
1:9.9.5.dfsg-3ubuntu0.9
1:9.9.5.dfsg-3ubuntu0.10
1:9.9.5.dfsg-3ubuntu0.11
1:9.9.5.dfsg-3ubuntu0.12
1:9.9.5.dfsg-3ubuntu0.13
1:9.9.5.dfsg-3ubuntu0.14
1:9.9.5.dfsg-3ubuntu0.15
1:9.9.5.dfsg-3ubuntu0.16
1:9.9.5.dfsg-3ubuntu0.17
1:9.9.5.dfsg-3ubuntu0.18
1:9.9.5.dfsg-3ubuntu0.19
1:9.9.5.dfsg-3ubuntu0.19+esm1
1:9.9.5.dfsg-3ubuntu0.19+esm2
1:9.9.5.dfsg-3ubuntu0.19+esm3
1:9.9.5.dfsg-3ubuntu0.19+esm4
1:9.9.5.dfsg-3ubuntu0.19+esm5
1:9.9.5.dfsg-3ubuntu0.19+esm6
1:9.9.5.dfsg-3ubuntu0.19+esm7
1:9.9.5.dfsg-3ubuntu0.19+esm9
1:9.9.5.dfsg-3ubuntu0.19+esm10

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "bind9",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "bind9-host",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "bind9utils",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "dnsutils",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "host",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "libbind-dev",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "libbind9-90",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "libdns100",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "libisc95",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "libisccc90",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "libisccfg90",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "liblwres90",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        },
        {
            "binary_name": "lwresd",
            "binary_version": "1:9.9.5.dfsg-3ubuntu0.19+esm11"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Ubuntu:Pro:16.04:LTS

bind9

Package

Name
bind9
Purl
pkg:deb/ubuntu/bind9@1:9.10.3.dfsg.P4-8ubuntu1.19+esm7?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.10.3.dfsg.P4-8ubuntu1.19+esm7

Affected versions

1:9.*

1:9.9.5.dfsg-11ubuntu1
1:9.9.5.dfsg-12
1:9.9.5.dfsg-12.1
1:9.9.5.dfsg-12.1ubuntu1
1:9.10.3.dfsg.P2-4
1:9.10.3.dfsg.P2-5
1:9.10.3.dfsg.P4-3
1:9.10.3.dfsg.P4-4
1:9.10.3.dfsg.P4-5
1:9.10.3.dfsg.P4-8
1:9.10.3.dfsg.P4-8ubuntu1
1:9.10.3.dfsg.P4-8ubuntu1.1
1:9.10.3.dfsg.P4-8ubuntu1.2
1:9.10.3.dfsg.P4-8ubuntu1.3
1:9.10.3.dfsg.P4-8ubuntu1.4
1:9.10.3.dfsg.P4-8ubuntu1.5
1:9.10.3.dfsg.P4-8ubuntu1.6
1:9.10.3.dfsg.P4-8ubuntu1.7
1:9.10.3.dfsg.P4-8ubuntu1.8
1:9.10.3.dfsg.P4-8ubuntu1.9
1:9.10.3.dfsg.P4-8ubuntu1.10
1:9.10.3.dfsg.P4-8ubuntu1.11
1:9.10.3.dfsg.P4-8ubuntu1.12
1:9.10.3.dfsg.P4-8ubuntu1.14
1:9.10.3.dfsg.P4-8ubuntu1.15
1:9.10.3.dfsg.P4-8ubuntu1.16
1:9.10.3.dfsg.P4-8ubuntu1.17
1:9.10.3.dfsg.P4-8ubuntu1.18
1:9.10.3.dfsg.P4-8ubuntu1.19
1:9.10.3.dfsg.P4-8ubuntu1.19+esm1
1:9.10.3.dfsg.P4-8ubuntu1.19+esm2
1:9.10.3.dfsg.P4-8ubuntu1.19+esm3
1:9.10.3.dfsg.P4-8ubuntu1.19+esm5
1:9.10.3.dfsg.P4-8ubuntu1.19+esm6

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "bind9",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "bind9-host",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "bind9utils",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "dnsutils",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "host",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libbind-dev",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libbind-export-dev",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libbind9-140",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libdns-export162",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libdns162",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libirs-export141",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libirs141",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libisc-export160",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libisc160",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libisccc-export140",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libisccc140",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libisccfg-export140",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "libisccfg140",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "liblwres141",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        },
        {
            "binary_name": "lwresd",
            "binary_version": "1:9.10.3.dfsg.P4-8ubuntu1.19+esm7"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}

Ubuntu:Pro:18.04:LTS

bind9

Package

Name
bind9
Purl
pkg:deb/ubuntu/bind9@1:9.11.3+dfsg-1ubuntu1.19+esm2?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.11.3+dfsg-1ubuntu1.19+esm2

Affected versions

1:9.*

1:9.10.3.dfsg.P4-12.6ubuntu1
1:9.11.2.P1-1ubuntu2
1:9.11.2.P1-1ubuntu3
1:9.11.2.P1-1ubuntu4
1:9.11.2.P1-1ubuntu5
1:9.11.3+dfsg-1ubuntu1
1:9.11.3+dfsg-1ubuntu1.1
1:9.11.3+dfsg-1ubuntu1.2
1:9.11.3+dfsg-1ubuntu1.3
1:9.11.3+dfsg-1ubuntu1.5
1:9.11.3+dfsg-1ubuntu1.7
1:9.11.3+dfsg-1ubuntu1.8
1:9.11.3+dfsg-1ubuntu1.9
1:9.11.3+dfsg-1ubuntu1.10
1:9.11.3+dfsg-1ubuntu1.11
1:9.11.3+dfsg-1ubuntu1.12
1:9.11.3+dfsg-1ubuntu1.13
1:9.11.3+dfsg-1ubuntu1.14
1:9.11.3+dfsg-1ubuntu1.15
1:9.11.3+dfsg-1ubuntu1.16
1:9.11.3+dfsg-1ubuntu1.17
1:9.11.3+dfsg-1ubuntu1.18
1:9.11.3+dfsg-1ubuntu1.19+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "bind9",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "bind9-host",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "bind9utils",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "dnsutils",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libbind-dev",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libbind-export-dev",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libbind9-160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libdns-export1100",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libdns1100",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libirs-export160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libirs160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libisc-export169",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libisc169",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libisccc-export160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libisccc160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libisccfg-export160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "libisccfg160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        },
        {
            "binary_name": "liblwres160",
            "binary_version": "1:9.11.3+dfsg-1ubuntu1.19+esm2"
        }
    ],
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}