PT-2022-4937 · Isc+12 · Bind+12

Published

2022-09-14

·

Updated

2024-07-25

·

CVE-2022-38178

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions prior to the fixed version
Description The issue is related to a flaw in the DNSSEC implementation of the BIND DNS server, specifically with the incorrect verification of the EdDSA cryptographic signature. This can be exploited by a remote attacker to trigger a small memory leak by spoofing the target resolver with responses that have a malformed EdDSA signature. Gradually, this can erode available memory to the point where the named service crashes due to lack of resources, effectively leading to a denial of service. The vulnerability can be exploited to severely degrade the resolver's performance.
Recommendations For BIND versions prior to the fixed version, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to the DNS resolution service to minimize the risk of exploitation. Avoid using the EdDSA algorithm in the affected DNSSEC implementation until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Verification of Cryptographic Signature

Memory Leak

Weakness Enumeration

Related Identifiers

ALSA-2022:6763
ALSA-2022:6778
ALSA-2022:6781
ALT-PU-2022-3048
ALT-PU-2022-3287
ALT-PU-2024-9772
ALT-PU-2024-9774
AZL-11002
AZL-39989
BDU:2022-06121
CESA-2022_6765
CESA-2022_6778
CESA-2022_6781
CVE-2022-38178
DLA-3138-1
DSA-5235-1
MGASA-2022-0388
OESA-2022-1981
OESA-2022-1982
OESA-2022-1983
OPENSUSE-SU-2022_3682-1
OPENSUSE-SU-2022_3729-1
OPENSUSE-SU-2022_3767-1
OPENSUSE-SU-2024:12356-1
RHSA-2022:6763
RHSA-2022:6764
RHSA-2022:6765
RHSA-2022:6778
RHSA-2022:6779
RHSA-2022:6780
RHSA-2022:6781
RHSA-2022:8598
RHSA-2022_6763
RHSA-2022_6765
RHSA-2022_6778
RHSA-2022_6781
RLSA-2022:6763
RLSA-2022:6778
RLSA-2022:6781
SUSE-SU-2022:3499-1
SUSE-SU-2022:3682-1
SUSE-SU-2022:3729-1
SUSE-SU-2022:3767-1
USN-5626-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu