The vendor explicitly states that these products are not affected by this CVE.
- bind as a component of Red Hat Enterprise Linux 10
- bind-chroot as a component of Red Hat Enterprise Linux 10
- bind-devel as a component of Red Hat Enterprise Linux 10
- bind-dnssec-utils as a component of Red Hat Enterprise Linux 10
- bind-doc as a component of Red Hat Enterprise Linux 10
- bind-libs as a component of Red Hat Enterprise Linux 10
- bind-license as a component of Red Hat Enterprise Linux 10
- bind-utils as a component of Red Hat Enterprise Linux 10
- bind.src as a component of Red Hat Enterprise Linux 10
- bind as a component of Red Hat Enterprise Linux 6
- bind-chroot as a component of Red Hat Enterprise Linux 6
- bind-devel as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in the `named` caching resolver, a component of BIND 9. When this resolver is configured to send EDNS Client Subnet (ECS) options, it may be vulnerable to a cache-poisoning attack. A remote attacker could exploit this to compromise the integrity of cached DNS data. This could lead to users being redirected to malicious websites or services. EDNS Client Subnet (ECS) options are only available in the BIND Subscription Edition (-S), so only the -S edition is affected by this CVE.
- Remediation
- No remediation text is recorded.
