RHSA-2020:4500MediumCVSS 7.5

Red Hat Security Advisory: bind security, bug fix, and enhancement update

Published
November 4, 2020
Last Modified
September 1, 2026

🔗 CVE IDs covered (4)

📋 Description

CVE-2020-8619 — bind: asterisk character in an empty non-terminal can cause an assertion failure in rbtdb.c CVE-2020-8622 — bind: truncated TSIG response can lead to an assertion failure CVE-2020-8623 — bind: remotely triggerable assertion failure in pk11.c CVE-2020-8624 — bind: incorrect enforcement of update-policy rules of type "subdomain"

🎯 Affected products173

  • Red Hat Enterprise Linux AppStream (v. 8)
  • Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-32:9.11.20-5.el8.src as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-chroot-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-chroot-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-chroot-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-chroot-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debuginfo-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 8)
  • bind-debugsource-32:9.11.20-5.el8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +143 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, the BIND daemon (named) will be restarted automatically. Workaround: As per upstream advisory: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

🔗 References (14)