High severity7.5NVD Advisory· Published Jun 21, 2023· Updated Jun 17, 2026
CVE-2023-2911
CVE-2023-2911
Description
If the recursive-clients quota is reached on a BIND 9 resolver configured with both stale-answer-enable yes; and stale-answer-client-timeout 0;, a sequence of serve-stale-related lookups could cause named to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33 through 9.16.41, 9.18.7 through 9.18.15, 9.16.33-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
21cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*+ 3 more
- cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*range: >=9.16.33,<=9.16.41
- cpe:2.3:a:isc:bind:*:*:*:*:supported_preview:*:*:*range: >=9.16.33,<=9.16.41
- (no CPE)range: 9.16.33-9.16.41, 9.18.7-9.18.15, 9.16.33-S1-9.16.41-S1, 9.18.11-S1-9.18.15-S1
- (no CPE)range: 9.16.33
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
- osv-coords7 versionspkg:rpm/opensuse/bind&distro=openSUSE%20Leap%2015.4pkg:rpm/opensuse/bind&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/bind&distro=openSUSE%20Tumbleweedpkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP4pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5
< 9.16.42-150400.5.27.1+ 6 more
- (no CPE)range: < 9.16.42-150400.5.27.1
- (no CPE)range: < 9.16.42-150500.8.3.1
- (no CPE)range: < 9.18.16-1.1
- (no CPE)range: < 9.16.42-150400.5.27.1
- (no CPE)range: < 9.16.42-150500.8.3.1
- (no CPE)range: < 9.16.42-150400.5.27.1
- (no CPE)range: < 9.16.42-150500.8.3.1
Patches
Vulnerability mechanics
References
6- www.openwall.com/lists/oss-security/2023/06/21/6nvdMailing ListPatchThird Party Advisory
- kb.isc.org/docs/cve-2023-2911nvdVendor Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/SEFCEVCTYEMKTWA7V7EYPI5YQQ4JWDLI/nvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/U3K6AJK7RRSR53HRF5GGKPA6PDUDWOD2/nvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20230703-0010/nvdThird Party Advisory
- www.debian.org/security/2023/dsa-5439nvdThird Party Advisory
News mentions
0No linked articles in our index yet.