CVE-2022-1183: Destroying a TLS session early causes assertion failure
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-1183?
CVE-2022-1183 is a vulnerability that can cause the named daemon to terminate with an assertion failure under certain configurations.
Which software is affected by CVE-2022-1183?
Vulnerable configurations include the ISC BIND software versions 9.18.0 to 9.18.2, as well as version 9.19.0. Netapp H410c Firmware is also affected.
What is the severity of CVE-2022-1183?
The severity of CVE-2022-1183 is considered high with a severity value of 7.5.
How can I fix CVE-2022-1183?
To fix CVE-2022-1183, update to a non-vulnerable version of ISC BIND or apply the recommended security patches provided by Netapp H410c Firmware.
Where can I find more information about CVE-2022-1183?
You can find more information about CVE-2022-1183 in the references: [ISC Knowledge Base](https://kb.isc.org/docs/cve-2022-1183) and [Netapp Security Advisory](https://security.netapp.com/advisory/ntap-20220707-0002/).