VDB
RHSA-2025%3A2441
RHSA-2025%3A2441
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in the bind package where a crafted DNS zone may generate numerous records in the 'Additional' section of the response. This flaw allows an attacker to send a large amount of such queries, which may lead either the authoritative server or an independent resolver to run into an uncontrolled CPU resource scenario, ultimately resulting in the server not being able to attend new requests and causing a denial of service as a consequence.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift4/ose-ibm-vpc-block-csi-driver-rhel8@sha256:f7c38b27c37bdb0c54f1b2ac6bed14d984cd3a184c0b014dbfb68c6b16d6fae7_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-docker-registry@sha256:a931d8eae1b9520ace25037566eb05292b20ea519d8cddd719511c45ac41892e_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-container-networking-plugins-rhel8@sha256:94288fbe4bc79925c62c7460201ca7b76325268f259581c57711009ff4fed523_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-container-networking-plugins-rhel8@sha256:94288fbe4bc79925c62c7460201ca7b76325268f259581c57711009ff4fed523_amd64, openshift4/ose-container-networking-plugins-rhel8@sha256:94288fbe4bc79925c62c7460201ca7b76325268f259581c57711009ff4fed523_amd64, * |
| Red Hat | openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:c1d89042a372d49072df19b639182cff24b8e0a5f599ea9c23c13c3830553cf2_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:c1d89042a372d49072df19b639182cff24b8e0a5f599ea9c23c13c3830553cf2_amd64, openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:c1d89042a372d49072df19b639182cff24b8e0a5f599ea9c23c13c3830553cf2_amd64, openshift4/ose-csi-snapshot-validation-webhook-rhel8@sha256:c1d89042a372d49072df19b639182cff24b8e0a5f599ea9c23c13c3830553cf2_amd64 |
| Red Hat | openshift4/ose-console-operator@sha256:b11863529e270047379701f36130d342bdac9121b8231f253894083dfbe32a34_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-cluster-update-keys@sha256:8ca1725aecd09493375a5d7e1f30afbd3023ea680feacbe354ba324e070ba115_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/egress-router-cni-rhel8@sha256:15147b23e2ed12026c164f42b3b2e1326c8c613d0535c700a15f6c37afd604c1_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/egress-router-cni-rhel8@sha256:15147b23e2ed12026c164f42b3b2e1326c8c613d0535c700a15f6c37afd604c1_amd64, *, openshift4/egress-router-cni-rhel8@sha256:15147b23e2ed12026c164f42b3b2e1326c8c613d0535c700a15f6c37afd604c1_amd64 |
| Red Hat | openshift4/ose-csi-external-provisioner@sha256:1a37804e5189938980f95eaf65929458f3ffce1fcde244501294bc4f03f69185_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-cluster-etcd-rhel8-operator@sha256:f6bc4e5eb79203e85a7232cabc6f71e7794157f1942d6da03b96f4ccd28ab088_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-kuryr-controller-rhel8@sha256:8a98cde73234a5a13659f182841703906f78d21809fc92eeb2456903f14b7f79_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-openstack-cinder-csi-driver-rhel8@sha256:ca0a900dd1a1bf86ad491c56a319a66eaede44ddf7befc350d49383a3b0a0c59_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-tools-rhel8@sha256:de48fba8f46f0acc7ce461218bfbfffe26ec43899fa78249357099b0cca685d6_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-tools-rhel8@sha256:de48fba8f46f0acc7ce461218bfbfffe26ec43899fa78249357099b0cca685d6_amd64, openshift4/ose-tools-rhel8@sha256:de48fba8f46f0acc7ce461218bfbfffe26ec43899fa78249357099b0cca685d6_amd64, openshift4/ose-tools-rhel8@sha256:de48fba8f46f0acc7ce461218bfbfffe26ec43899fa78249357099b0cca685d6_amd64 |
| Red Hat | openshift4/ose-installer@sha256:f7d2c4328603f6c98673aeba4078f89bbc847e18fea164396f50bd3bf66a0630_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-vsphere-cloud-controller-manager-rhel8@sha256:2373b56fe0e62a41c9287b1923864c2805941ee6df8156c9b5a0cce99ba4821a_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-openshift-controller-manager-rhel8@sha256:b919c946b5dcb8a194f7cf556b0151ad18afb27930e1136cc02d7a1f1f30da17_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-openshift-controller-manager-rhel8@sha256:b919c946b5dcb8a194f7cf556b0151ad18afb27930e1136cc02d7a1f1f30da17_amd64, openshift4/ose-openshift-controller-manager-rhel8@sha256:b919c946b5dcb8a194f7cf556b0151ad18afb27930e1136cc02d7a1f1f30da17_amd64, openshift4/ose-openshift-controller-manager-rhel8@sha256:b919c946b5dcb8a194f7cf556b0151ad18afb27930e1136cc02d7a1f1f30da17_amd64 |
| Red Hat | openshift4/ose-baremetal-machine-controllers@sha256:a69cf9756301de9e1d5606cfcdd8d34d164d27251ec1997b0e18813b925db7f9_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-baremetal-machine-controllers@sha256:a69cf9756301de9e1d5606cfcdd8d34d164d27251ec1997b0e18813b925db7f9_amd64, *, openshift4/ose-baremetal-machine-controllers@sha256:a69cf9756301de9e1d5606cfcdd8d34d164d27251ec1997b0e18813b925db7f9_amd64 |
| Red Hat | openshift4/ose-docker-builder@sha256:1f78f7c5079859fae18c90057c462784f5dddd9b60ba67a9d8319d701df409f2_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | openshift4/ose-docker-builder@sha256:1f78f7c5079859fae18c90057c462784f5dddd9b60ba67a9d8319d701df409f2_amd64, openshift4/ose-docker-builder@sha256:1f78f7c5079859fae18c90057c462784f5dddd9b60ba67a9d8319d701df409f2_amd64, openshift4/ose-docker-builder@sha256:1f78f7c5079859fae18c90057c462784f5dddd9b60ba67a9d8319d701df409f2_amd64 |
| Red Hat | openshift4/ose-oauth-proxy@sha256:78bdc690a012f67b2e0938ba9a4a80ec58960a36af0e2c7276f2e76b128a1997_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-tests@sha256:f75bf588909e5a8ef9f39313e229fc871616a9b538c1bf9eb075d09a749c6194_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, * |
| Red Hat | openshift4/ose-csi-external-snapshotter@sha256:ad8b3c84ac6e3ad633b5c63f8066507053ab83dcaa64c6d2548a6d334c4da7fa_amd64 as a component of Red Hat OpenShift Container Platform 4.12 | *, *, openshift4/ose-csi-external-snapshotter@sha256:ad8b3c84ac6e3ad633b5c63f8066507053ab83dcaa64c6d2548a6d334c4da7fa_amd64 |
…and 364 more
Timeline
- Mar 13, 2025 CVE Published
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Distribution Patch
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Apr 24, 2026 Security Advisory
- Jul 13, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2025:2441 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/security/vulnerabilities/RHSB-2024-001 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2258725 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2326231 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2327169 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2333122 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2342879 issue
- https://issues.redhat.com/browse/OCPBUGS-48086 advisory
- https://issues.redhat.com/browse/OCPBUGS-49644 advisory
- https://issues.redhat.com/browse/OCPBUGS-50880 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_2441.json advisory
- https://access.redhat.com/security/cve/CVE-2024-11187 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-11187 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-11187 advisory
- https://kb.isc.org/docs/cve-2024-11187 advisory
- https://access.redhat.com/security/cve/CVE-2024-11218 advisory
- https://www.cve.org/CVERecord?id=CVE-2024-11218 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-11218 advisory
- https://github.com/containers/buildah/pull/5918 advisory
…and 17 more