CVE-2022-2795: Processing large delegations may severely degrade resolver performance
A flaw was found in bind. When flooding the target resolver with special queries, an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
Other sources
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
Processing large delegations may severely degrade resolver performance
— Microsoft
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2022-2795.
What is the severity of CVE-2022-2795?
The severity of CVE-2022-2795 is medium with a severity value of 5.3.
How does the vulnerability CVE-2022-2795 impact the target resolver?
The vulnerability CVE-2022-2795 allows an attacker to significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
What software versions are affected by CVE-2022-2795?
The software versions affected by CVE-2022-2795 include bind 9.16.33, bind 9.18.7, bind 9.19.5, and corresponding versions in Red Hat and Debian distributions.
Are there any known remedies for CVE-2022-2795?
Yes, there are known remedies for CVE-2022-2795 which include upgrading to specific versions of bind like 9.16.44-1~deb11u1 or applying patches provided by Red Hat and Debian.