PT-2022-4938 · Isc+11 · Bind+11

Anat Bremler-Barr

+2

·

Published

2022-08-18

·

Updated

2026-01-30

·

CVE-2022-2795

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions (affected versions not specified)
Description The issue is related to a flaw in the resolver code of the DNS server, which can be exploited by flooding the target resolver with queries, significantly impairing its performance and effectively denying legitimate clients access to the DNS resolution service. This can lead to a denial of service (DoS) attack. The vulnerability is associated with improper management of internal resources within the application when handling large delegations.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Improper Verification of Cryptographic Signature

Resource Exhaustion

Special Elements Injection

Memory Leak

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALSA-2023:2261
ALSA-2023:2792
ALSA-2023:3002
ALT-PU-2022-3048
ALT-PU-2022-3287
ALT-PU-2024-9772
ALT-PU-2024-9774
AZL-10999
AZL-39992
BDU:2022-05984
BDU:2022-06070
BDU:2022-06120
BDU:2022-06121
BDU:2022-06124
BDU:2022-06125
CESA-2023_0402
CESA-2023_2792
CESA-2023_3002
CVE-2022-2795
DLA-3138-1
DSA-5235-1
MGASA-2022-0388
OESA-2022-1981
OESA-2022-1982
OESA-2022-1983
OPENSUSE-SU-2022_3682-1
OPENSUSE-SU-2022_3729-1
OPENSUSE-SU-2022_3767-1
OPENSUSE-SU-2024:12356-1
RHSA-2023:0402
RHSA-2023:2261
RHSA-2023:2792
RHSA-2023:3002
RHSA-2023_0402
RHSA-2023_2261
RHSA-2023_2792
RHSA-2023_3002
RHSA-2024:2720
ROSA-SA-2023-2121
SUSE-SU-2022:3499-1
SUSE-SU-2022:3500-1
SUSE-SU-2022:3682-1
SUSE-SU-2022:3729-1
SUSE-SU-2022:3767-1
SUSE-SU-2022_3499-1
SUSE-SU-2022_3500-1
SUSE-SU-2022_3682-1
SUSE-SU-2022_3729-1
SUSE-SU-2022_3767-1
USN-5626-1
USN-5626-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Suse
Ubuntu