Red Hat released Important security updates for BIND addressing CVE-2024-1975 and CVE-2024-1737, denial-of-service flaws affecting DNS resolvers and authoritative servers. CVE-2024-1975 allows clients to exhaust CPU resources with streams of SIG(0)-signed requests when a server hosts a KEY record or a validating resolver has cached one. CVE-2024-1737 causes severe database and query-performance degradation when a single hostname contains very large numbers of resource records. Affected upstream BIND releases include 9.11 through 9.11.37, 9.16 through 9.16.50, 9.18 through 9.18.27, and 9.19 through 9.19.24, with CVE-2024-1975 also affecting releases from 9.0.0 onward.
The fixes are available across supported RHEL 8 and RHEL 9 update channels and OpenShift Container Platform 4.12 through 4.16. Red Hat advisories provide updated packages including 9.11.36-16.el8_10.2 for RHEL 8, 9.11.36-8.el8_8.6 for RHEL 8.8 channels, and 9.16.23-11.el9_2.5 for RHEL 9.2; selected RHEL 8.6 and RHEL 9.2 channels also remediate CVE-2024-4076, an assertion-failure condition when serving stale cache data and authoritative-zone content. Organizations should apply the applicable BIND updates promptly, prioritizing exposed recursive resolvers and authoritative DNS infrastructure.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2024:6013, releasing OpenShift Container Platform 4.15.30 images and packages for RHEL 8 and 9. The update fixed BIND CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076, plus Helm CVE-2024-26147.
Red Hat issued RHSA-2024:6009, releasing OpenShift Container Platform 4.13.49 for supported RHEL 8 and RHEL 9 architectures. The Important update fixed BIND CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076, along with CoreDNS CVE-2024-0874, go-retryablehttp CVE-2024-6104, and other security issues.
Red Hat issued Important advisory RHSA-2024:5930 for RHEL 7 Extended Lifecycle Support, providing bind-9.11.4-26.P2.el7_9.17 packages for x86_64, s390x, ppc64, and ppc64le. The update remediated the BIND denial-of-service vulnerabilities CVE-2024-1737 and CVE-2024-1975.
Red Hat issued Important advisory RHSA-2024:5894 for BIND on RHEL Server 7.7 Advanced Update Support for x86_64. The update supplied BIND 9.11.4-9.P2.el7_7.7 and remediated CVE-2024-1737 and CVE-2024-1975 denial-of-service vulnerabilities.
Red Hat issued Important advisory RHSA-2024:5908 for RHEL 8.6 Extended Life Cycle Long Life, AUS, TUS, and SAP update-service offerings. The update supplied BIND 9.11.36-3.el8_6.9 and remediated CVE-2024-1737 and CVE-2024-1975 denial-of-service vulnerabilities.
Red Hat issued Important advisory RHSA-2024:5907 for RHEL 9.0 update-service offerings, updating BIND to 9.16.23-1.el9_0.7 and bind-dyndb-ldap to 11.9-7.el9_0.3. The update remediated CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076 for applicable SAP and four-year update-service architectures.
Red Hat issued Important advisory RHSA-2024:5871 for supported RHEL 8.4 update-service variants, supplying bind-9.11.26-4.el8_4.6 packages. The update remediated CVE-2024-1737 and CVE-2024-1975 across applicable AUS, TUS, SAP Solutions, and Extended Life Cycle Long Life channels.
Red Hat issued Important advisory RHSA-2024:5838 for RHEL 8.8 supported update channels, providing BIND version 9.11.36-8.el8_8.6. The update remediated CVE-2024-1737 and CVE-2024-1975 across EUS, TUS, SAP Solutions, and Extended Life Cycle Long Life offerings.
Red Hat issued Important advisory RHSA-2024:5813 for RHEL 9.2 support channels, updating BIND to 9.16.23-11.el9_2.5 and bind-dyndb-ldap to 11.9-8.el9_2.3. The advisory remediated CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076.
Red Hat published Important advisory RHSA-2024:5655 for RHEL Server AUS 8.2 on x86_64, supplying BIND 9.11.13-6.el8_2.9. It remediated CVE-2024-1737 and CVE-2024-1975 denial-of-service risks.
Red Hat issued Important advisory RHSA-2024:5525 for RHEL 8.8 Extended Update Support and associated repositories, supplying bind9.16 9.16.23-0.14.el8_8.5. The update remediated CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076 on supported RHEL 8.8 architectures and lifecycle offerings.
Red Hat published Important advisory RHSA-2024:5524 for RHEL 8, providing fixed BIND packages version 9.11.36-16.el8_10.2. The update addressed database slowdown caused by many records at one name and SIG(0)-based CPU exhaustion.
Red Hat issued Important advisory RHSA-2024:5418 for selected RHEL 8.6 support channels, updating bind9.16 to 9.16.23-0.7.el8_6.6. The update remediated CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076.
Red Hat issued Important advisory RHSA-2024:5390 for RHEL 8.10, providing bind9.16 version 9.16.23-0.22.el8_10. The update remediated CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076 for supported RHEL 8 architectures and RHEL 8.10 Extended Life Cycle releases.
Red Hat issued Important advisory RHSA-2024:5231 for RHEL 9, updating BIND to 9.16.23-18.el9_4.6 and bind-dyndb-ldap to 11.9-10.el9_4. The update remediated CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076 across supported RHEL 9 architectures and lifecycle channels.
Red Hat stated that no mitigation meeting its deployment, applicability, and stability criteria was available for CVE-2024-1737. It also said the DHCP package in RHEL 9 is not affected because its DDNS and configuration routines do not expose the vulnerable BIND-library code path.
Red Hat issued RHSA advisories addressing CVE-2024-1737 and CVE-2024-1975 in Red Hat OpenShift Container Platform versions 4.12 through 4.16 during September 3–18, 2024.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
21 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.