First published: Wed Sep 21 2022(Updated: )
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
Credit: security-officer@isc.org
Affected Software | Affected Version | How to fix |
---|---|---|
ISC BIND | >=9.18.0<9.18.7 | |
ISC BIND | >=9.19.0<9.19.5 |
Upgrade to the patched release most closely related to your current version of BIND: BIND 9.18.7 or BIND 9.19.5.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2881 is a vulnerability in the ISC BIND software that may cause read past end of the buffer and either read memory it should not read or crash the process.
CVE-2022-2881 has a severity level of 8.2 (high).
The ISC BIND software versions 9.18.0 up to 9.18.7 and versions 9.19.0 up to 9.19.5 are affected by CVE-2022-2881.
To fix CVE-2022-2881, it is recommended to update the ISC BIND software to a version that is not affected by this vulnerability.
More information about CVE-2022-2881 can be found at the following references: http://www.openwall.com/lists/oss-security/2022/09/21/3, https://kb.isc.org/docs/cve-2022-2881, https://security.gentoo.org/glsa/202210-25