Unrated severityNVD Advisory· Published Feb 13, 2024· Updated Mar 17, 2025
Cleaning an ECS-enabled cache may cause excessive CPU load
CVE-2023-5680
Description
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
Affected products
17- osv-coords16 versionspkg:apk/chainguard/bindpkg:apk/chainguard/bind-devpkg:apk/chainguard/bind-dnssec-rootpkg:apk/chainguard/bind-dnssec-toolspkg:apk/chainguard/bind-docpkg:apk/chainguard/bind-libspkg:apk/chainguard/bind-pluginspkg:apk/chainguard/bind-toolspkg:apk/wolfi/bindpkg:apk/wolfi/bind-devpkg:apk/wolfi/bind-dnssec-rootpkg:apk/wolfi/bind-dnssec-toolspkg:apk/wolfi/bind-docpkg:apk/wolfi/bind-libspkg:apk/wolfi/bind-pluginspkg:apk/wolfi/bind-tools
< 9.18.25-r0+ 15 more
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- (no CPE)range: < 9.18.25-r0
- ISC/BIND 9v5Range: 9.11.3-S1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- kb.isc.org/docs/cve-2023-5680mitrevendor-advisory
- security.netapp.com/advisory/ntap-20240503-0005/mitre
News mentions
0No linked articles in our index yet.