PT-2023-1302 · Isc+9 · Bind 9+9

Rob Schulhof

·

Published

2023-01-25

·

Updated

2025-04-01

·

CVE-2022-3094

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.16.0 through 9.16.36 BIND 9 versions 9.18.0 through 9.18.10 BIND 9 versions 9.19.0 through 9.19.8 BIND 9 versions 9.16.8-S1 through 9.16.36-S1
Description The issue is related to the allocation of large amounts of memory by named when sending a flood of dynamic DNS updates. This can cause named to exit due to a lack of free memory. The scope of this issue is limited to trusted clients who are permitted to make dynamic zone changes. Memory is allocated prior to the checking of access permissions and is retained during the processing of a dynamic update from a client whose access credentials are accepted. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore, it is only likely to be possible to degrade or stop named by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome.
Recommendations For BIND 9 versions 9.16.0 through 9.16.36, update to a version that includes the fix for this issue. For BIND 9 versions 9.18.0 through 9.18.10, update to a version that includes the fix for this issue. For BIND 9 versions 9.19.0 through 9.19.8, update to a version that includes the fix for this issue. For BIND 9 versions 9.16.8-S1 through 9.16.36-S1, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to dynamic updates to minimize the risk of exploitation.

Fix

DoS

RCE

Resource Exhaustion

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:2261
ALSA-2023:2792
ALSA-2023:7177
ALT-PU-2023-1130
ALT-PU-2023-1185
AZL-13204
BDU:2023-00580
CESA-2023_2792
CESA-2023_7177
CVE-2022-3094
DSA-5329-1
OESA-2023-1067
OESA-2023-1068
OPENSUSE-SU-2023_0341-1
OPENSUSE-SU-2023_0427-1
OPENSUSE-SU-2024:12641-1
RHSA-2023:2261
RHSA-2023:2792
RHSA-2023:7177
RHSA-2023_2261
RHSA-2023_2792
RHSA-2023_7177
RHSA-2024:1406
RHSA-2024:2720
SUSE-SU-2023:0341-1
SUSE-SU-2023:0427-1
SUSE-SU-2023_0341-1
SUSE-SU-2023_0427-1
USN-5827-1

Affected Products

Alt Linux
Almalinux
Bind 9
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Suse
Ubuntu