CVE-2022-0396: DoS from specifically crafted TCP packets
A flaw was found in Bind that incorrectly handles certain crafted TCP streams. The vulnerability allows TCP connection slots to be consumed for an indefinite time frame via a specifically crafted TCP stream sent from a client. This flaw allows a remote attacker to send specially crafted TCP streams with 'keep-response-order' enabled that could cause connections to BIND to remain in CLOSEWAIT status for an indefinite period, even after the client has terminated the connection. This issue results in BIND consuming resources, leading to a denial of service.
Other sources
BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSEWAIT status for an indefinite period of time, even after the client has terminated the connection.
ISC recently discovered an issue in BIND that allows TCP connection slots to be consumed for an indefinite time frame via a specifically crafted TCP stream sent from a client. This issue is present in BIND 9.16.11 to 9.16.26 (including S editions), and 9.18.0.
This issue can only be triggered on BIND servers which have keep-response-order enabled, which is not the default configuration. The keep-response-order option is an ACL block, and as such, any hosts specified within it will be able to trigger this issue on affected.
— Red Hat
Affected Software
Remediation
Information
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this BIND vulnerability?
The vulnerability ID for this BIND vulnerability is CVE-2022-0396.
What is the severity of CVE-2022-0396?
The severity of CVE-2022-0396 is medium.
How does the BIND vulnerability affect the software?
The BIND vulnerability affects versions 9.16.11 to 9.16.26, 9.17.0 to 9.18.0, and versions 9.16.11-S1 to 9.16.26-S1 of BIND Supported.
How can a remote attacker exploit CVE-2022-0396?
A remote attacker can exploit CVE-2022-0396 by sending specially crafted TCP streams to consume TCP connection slots indefinitely.
What is the recommended remedy for CVE-2022-0396?
The recommended remedy for CVE-2022-0396 is to update to BIND version 9.16.27 or 9.18.1 depending on the affected version.