CVE-2024-11187
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 16.73%
- CWE
- CWE-405
- Published
- 2025-01-29
- Last modified
- 2026-03-13
Affected products
- ISC BIND 9
- ISC BIND 9
- ISC BIND 9
- ISC BIND 9
- ISC BIND 9
- ISC BIND 9
- ISC BIND 9
- ISC BIND 9
Weakness type
Related vulnerabilities
- CVE-2026-54874 — Excessive Memory Use Buffering DTLS Records for a Future Epoch
- CVE-2026-25611 — Pre-Authentication Memory Exhaustion Denial of Service in MongoDB Server
- CVE-2025-53633 — Chall-Manager's scenario decoding process does not check for zip bombs
- CVE-2024-56200 — Uncontrolled Recursion and Asymmetric Resource Consumption in Altair media/file proxy
- CVE-2021-38447 — OCI OpenDDS Secure Amplification
- CVE-2025-42874 — Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
- CVE-2024-45590 — body-parser vulnerable to denial of service when url encoding is enabled
- CVE-2024-55628 — Suricata oversized resource names utilizing DNS name compression can lead to resource starvation