CVE-2022-2881: Buffer overread in statistics channel code
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-2881?
CVE-2022-2881 is a vulnerability in the ISC BIND software that may cause read past end of the buffer and either read memory it should not read or crash the process.
What is the severity of CVE-2022-2881?
CVE-2022-2881 has a severity level of 8.2 (high).
Which software is affected by CVE-2022-2881?
The ISC BIND software versions 9.18.0 up to 9.18.7 and versions 9.19.0 up to 9.19.5 are affected by CVE-2022-2881.
How can CVE-2022-2881 be fixed?
To fix CVE-2022-2881, it is recommended to update the ISC BIND software to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2022-2881?
More information about CVE-2022-2881 can be found at the following references: http://www.openwall.com/lists/oss-security/2022/09/21/3, https://kb.isc.org/docs/cve-2022-2881, https://security.gentoo.org/glsa/202210-25