PT-2022-6539 · Isc+9 · Bind+9

Published

2022-03-16

·

Updated

2024-06-15

·

CVE-2022-0396

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions BIND versions 9.16.11 through 9.16.26 BIND versions 9.17.0 through 9.18.0 BIND Supported Preview Edition versions 9.16.11-S1 through 9.16.26-S1
Description The issue is related to improper resource cleanup, which can be exploited by a remote attacker sending specially crafted TCP streams with 'keep-response-order' enabled. This can cause connections to remain in CLOSE WAIT status for an indefinite period, even after the client has terminated the connection.
Recommendations For BIND versions 9.16.11 through 9.16.26, update to a version outside of this range to resolve the issue. For BIND versions 9.17.0 through 9.18.0, update to a version outside of this range to resolve the issue. For BIND Supported Preview Edition versions 9.16.11-S1 through 9.16.26-S1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of TCP streams with 'keep-response-order' enabled to minimize the risk of exploitation.

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7643
ALSA-2022:8068
AZL-9119
BDU:2023-02158
CESA-2022_7643
CVE-2022-0396
DSA-5105-1
OESA-2022-1615
OPENSUSE-SU-2022_2713-1
OPENSUSE-SU-2024:12081-1
RHSA-2022:7643
RHSA-2022:8068
RHSA-2022_7643
RHSA-2022_8068
RLSA-2022:7643
RLSA-2022:8068
SUSE-SU-2022:2713-1
USN-5332-1

Affected Products

Almalinux
Bind
Bind Server
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu