CVE-2022-3736: named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
A flaw was found in Bind, where a resolver crash is possible. When stale cache and stale answers are enabled, the option stale-answer-client-timeout is set to a positive integer, and the resolver receives an RRSIG query.
Other sources
BIND 9 resolver can crash when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
— MITRE
BIND 9 resolver can crash when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to a positive integer, and the resolver receives an RRSIG query.
— Red Hat
Affected Software
Remediation
Information
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in Bind?
The vulnerability ID for this flaw in Bind is CVE-2022-3736.
What is the severity level of CVE-2022-3736?
The severity level of CVE-2022-3736 is high with a severity value of 7.
How does CVE-2022-3736 affect Bind?
CVE-2022-3736 affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.1...
How can I fix the vulnerability in Bind?
To fix the vulnerability in Bind, update to version 9.16.37, 9.18.11, 9.19.9, 32:9.16.23-0.14.el8, or 32:9.16.23-11.el9.
Where can I find more information about CVE-2022-3736?
You can find more information about CVE-2022-3736 at the following references: https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2164507, https://access.redhat.com/errata/RHSA-2023:2261, https://access.redhat.com/errata/RHSA-2023:2792.