CVE-2024-4076 is a denial-of-service vulnerability in BIND 9 in which a client query can trigger an assertion failure when the server simultaneously serves stale cached data and performs a lookup against local authoritative zone content. The resulting crash can terminate DNS service; Red Hat rates the issue as Important with a CVSS v3.1 score of 7.5, citing network exploitability, no required privileges or user interaction, and high availability impact.
Affected upstream versions are BIND 9.16.13–9.16.50, 9.18.0–9.18.27, and 9.19.0–9.19.24. Red Hat issued security errata for affected Red Hat Enterprise Linux 8 and 9 package streams and OpenShift Container Platform 4.13–4.16, and reports no qualifying standalone mitigation; organizations should apply the relevant updated BIND packages. The flaw is an instance of CWE-617: Reachable Assertion, where attacker-controlled input reaches an assertion condition and causes an availability-impacting process termination.

See affected versions and whether adversaries are exploiting it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:5390 to fix CVE-2024-4076 in the RHEL 8 bind9.16 package stream.
Red Hat released RHSA-2024:5907 to address CVE-2024-4076 for RHEL 9.0 Update Services for SAP Solutions systems using bind and bind-dyndb-ldap.
Red Hat released RHSA-2024:5813 to fix CVE-2024-4076 in the RHEL 9.2 Extended Update Support bind package stream.
Red Hat released RHSA-2024:5525 to address CVE-2024-4076 for RHEL 8.8 Extended Update Support systems using bind9.16.
Red Hat released RHSA-2024:5418 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions. It also released RHSA-2024:5231 for RHEL 9 bind and bind-dyndb-ldap packages.
CVE-2024-4076 was documented as a reachable-assertion flaw in BIND 9: queries that simultaneously serve stale cache data and perform local authoritative lookups can crash the DNS server. Affected upstream versions include 9.16.13–9.16.50, 9.18.0–9.18.27, and 9.19.0–9.19.24.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.