PT-2022-25268 · Unknown+4 · Knot Resolver+4

Published

2022-09-23

·

Updated

2024-02-14

·

CVE-2022-40188

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Knot Resolver versions prior to 5.5.3
Description The issue allows remote attackers to cause a denial of service due to algorithmic complexity, resulting in CPU consumption. This occurs when an authoritative server returns large NS sets or address sets during an attack.
Recommendations For versions prior to 5.5.3, update to version 5.5.3 or later to resolve the issue.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2696
ALT-PU-2024-2060
CVE-2022-40188
DLA-3139-1
USN-6225-1

Affected Products

Alt Linux
Debian
Knot Resolver
Linuxmint
Ubuntu