PT-2022-4936 · Isc+12 · Bind+12

Published

2022-09-14

·

Updated

2026-01-16

·

CVE-2022-38177

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions prior to the fixed version
Description The issue is related to a memory leak in the DNSSEC code for the ECDSA algorithm. By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. This can allow a remote attacker to perform a denial-of-service attack.
Recommendations For BIND versions prior to the fixed version, update to a version that includes the fix for this issue to prevent the memory leak and potential crash. As a temporary workaround, consider restricting access to the DNSSEC validation code to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Verification of Cryptographic Signature

Memory Leak

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:6763
ALSA-2022:6778
ALSA-2022:6781
ALT-PU-2022-3048
ALT-PU-2022-3287
ALT-PU-2024-9772
ALT-PU-2024-9774
AZL-11001
AZL-39986
BDU:2022-06120
CESA-2022_6765
CESA-2022_6778
CESA-2022_6781
CVE-2022-38177
DLA-3138-1
DSA-5235-1
MGASA-2022-0388
OESA-2022-1981
OESA-2022-1982
OESA-2022-1983
OPENSUSE-SU-2022_3682-1
OPENSUSE-SU-2022_3729-1
OPENSUSE-SU-2022_3767-1
RHSA-2022:6763
RHSA-2022:6764
RHSA-2022:6765
RHSA-2022:6778
RHSA-2022:6779
RHSA-2022:6780
RHSA-2022:6781
RHSA-2022:8598
RHSA-2022_6763
RHSA-2022_6765
RHSA-2022_6778
RHSA-2022_6781
RLSA-2022:6763
RLSA-2022:6778
RLSA-2022:6781
SUSE-SU-2022:3499-1
SUSE-SU-2022:3500-1
SUSE-SU-2022:3682-1
SUSE-SU-2022:3729-1
SUSE-SU-2022:3767-1
USN-5626-1
USN-5626-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu