CVE-2022-38177: Memory leak in ECDSA DNSSEC verification code
A flaw was found in the Bind package. By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak, resulting in crashing the program.
Other sources
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Memory leak in ECDSA DNSSEC verification code
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.4-26.P2.el7_9.10 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.36-3.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 32:9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.4-26.P2.el8_1.6 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.26-4.el8_4.1 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.16.23-1.el9_0.1 - Upgrade
Upgrade
debian/bind9to a version that resolves this vulnerability.Fixed in 1:9.11.5.P4+dfsg-5.1+deb10u9Fixed in 1:9.16.44-1~deb11u1Fixed in 1:9.18.19-1~deb12u1Fixed in 1:9.19.17-1 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.16.33 - Upgrade
Upgrade
BINDto a version that resolves this vulnerability.Fixed in 9.16.33 - Upgrade
Upgrade
BIND (Supported Preview Edition)to a version that resolves this vulnerability.Fixed in 9.16.33-S1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in the Bind package?
The vulnerability ID for this flaw in the Bind package is CVE-2022-38177.
What is the severity rating of CVE-2022-38177?
The severity rating of CVE-2022-38177 is high, with a value of 7.5.
What is the impact of CVE-2022-38177?
CVE-2022-38177 allows an attacker to trigger a small memory leak, potentially causing named to crash.
Which software versions are affected by CVE-2022-38177?
Software versions up to and excluding 9.16.33 of the Bind package are affected by CVE-2022-38177.
Where can I find more information about CVE-2022-38177?
You can find more information about CVE-2022-38177 in the references provided: [link1] [link2] [link3].