{"id":"CGA-99p6-8fc4-hwvw","modified":"2026-07-17T18:48:25.653231894Z","published":"2025-10-30T21:48:02Z","upstream":["CVE-2023-50387","GHSA-8459-gg55-8qjj"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00001.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00035.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20240307-0007/"},{"type":"ADVISORY","url":"https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1219823"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/02/16/2"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2024/02/16/3"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2023-50387"},{"type":"WEB","url":"https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2023-50387"},{"type":"WEB","url":"https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html"},{"type":"WEB","url":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=39367411"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=39372384"},{"type":"WEB","url":"https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/"},{"type":"WEB","url":"https://www.athene-center.de/aktuelles/key-trap"},{"type":"WEB","url":"https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdf"},{"type":"WEB","url":"https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/"},{"type":"WEB","url":"https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50387.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50387"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html"},{"type":"ARTICLE","url":"https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html"},{"type":"ARTICLE","url":"https://www.isc.org/blogs/2024-bind-security-release/"}],"affected":[{"package":{"name":"bind","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/bind?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.18.24-r0"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2024-02-13T17:46:23Z","architecture":"x86_64","component_name":"bind","component_version":"","component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/bind","latest_event_status":"fixed"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-99p6-8fc4-hwvw.json"}},{"package":{"name":"bind","ecosystem":"Wolfi","purl":"pkg:apk/wolfi/bind?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.18.24-r0"}]}],"ecosystem_specific":{"components":[{"latest_event_timestamp":"2024-02-13T17:46:23Z","architecture":"x86_64","component_name":"bind","component_version":"","component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/bind","latest_event_status":"fixed"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-99p6-8fc4-hwvw.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}