The vendor explicitly identifies these products as affected by this CVE.
- bind as a component of Red Hat Enterprise Linux 10
- bind-chroot as a component of Red Hat Enterprise Linux 10
- bind-devel as a component of Red Hat Enterprise Linux 10
- bind-dnssec-utils as a component of Red Hat Enterprise Linux 10
- bind-doc as a component of Red Hat Enterprise Linux 10
- bind-libs as a component of Red Hat Enterprise Linux 10
- bind-license as a component of Red Hat Enterprise Linux 10
- bind-utils as a component of Red Hat Enterprise Linux 10
- bind.src as a component of Red Hat Enterprise Linux 10
- Summary
- A flaw was found in BIND, specifically in the named server's handling of DNS queries signed with SIG(0). A remote attacker could exploit this use-after-return vulnerability by sending a specially-crafted DNS request. This could cause an Access Control List (ACL) to improperly match an IP address, potentially leading to unauthorized access to resources.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
