CVE-2022-38177: Memory leak in ECDSA DNSSEC verification code
A flaw was found in the Bind package. By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak, resulting in crashing the program.
Other sources
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Memory leak in ECDSA DNSSEC verification code
— Microsoft
Affected Software
Remediation
Patch Available
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID for this flaw in the Bind package?
The vulnerability ID for this flaw in the Bind package is CVE-2022-38177.
What is the severity rating of CVE-2022-38177?
The severity rating of CVE-2022-38177 is high, with a value of 7.5.
What is the impact of CVE-2022-38177?
CVE-2022-38177 allows an attacker to trigger a small memory leak, potentially causing named to crash.
Which software versions are affected by CVE-2022-38177?
Software versions up to and excluding 9.16.33 of the Bind package are affected by CVE-2022-38177.
Where can I find more information about CVE-2022-38177?
You can find more information about CVE-2022-38177 in the references provided: [link1] [link2] [link3].