Red Hat addressed CVE-2024-11187, an Important BIND 9 denial-of-service flaw in which specially constructed DNS zones can cause responses to contain excessive Additional-section records. Attackers able to repeatedly query those records can drive disproportionate CPU consumption on authoritative DNS servers or independent resolvers; exploitation generally depends on a zone deliberately built to trigger the condition.
The fix was shipped in Red Hat OpenShift Container Platform releases including 4.17.19 and 4.16.37. The 4.16.37 update also remediates CVE-2024-12705, covering several DNS-over-HTTPS issues under heavy query load. Red Hat recommends that affected OpenShift deployments upgrade through their applicable release channels using the OpenShift CLI or web console.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2025:1912, an Important security advisory releasing OpenShift Container Platform 4.17.19 container images. The release fixes CVE-2024-11187 in BIND 9, where DNS messages with many Additional-section records can cause CPU exhaustion.
Red Hat published RHSA-2025:1907, an Important security advisory releasing OpenShift Container Platform 4.16.37 container images. The update fixes BIND 9 CPU-exhaustion flaw CVE-2024-11187 and DNS-over-HTTPS issues tracked as CVE-2024-12705.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.