CVE-2022-38178: Memory leaks in EdDSA DNSSEC verification code
A flaw was found in the Bind package, where the DNSSEC verification code for the EdDSA algorithm leaks memory when there is a signature length mismatch. By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak, resulting in crashing the program.
Other sources
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Memory leaks in EdDSA DNSSEC verification code
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.4-26.P2.el7_9.10 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.36-3.el8_6.1 - Upgrade
Upgrade
redhat/bind9.16to a version that resolves this vulnerability.Fixed in 32:9.16.23-0.7.el8_6.1 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.4-26.P2.el8_1.6 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.13-6.el8_2.4 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.11.26-4.el8_4.1 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 32:9.16.23-1.el9_0.1 - Upgrade
Upgrade
debian/bind9to a version that resolves this vulnerability.Fixed in 1:9.11.5.P4+dfsg-5.1+deb10u9Fixed in 1:9.16.44-1~deb11u1Fixed in 1:9.18.19-1~deb12u1Fixed in 1:9.19.17-1 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.16.33 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.18.7 - Upgrade
Upgrade
redhat/bindto a version that resolves this vulnerability.Fixed in 9.19.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.16.33 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.18.7 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.19.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.16.33-S1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-38178?
CVE-2022-38178 is a vulnerability in the Bind package that allows an attacker to trigger a small memory leak by spoofing the target resolver with responses that have a malformed EdDSA signature.
What is the severity of CVE-2022-38178?
CVE-2022-38178 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2022-38178?
The Bind package versions 9.16.33, 9.18.7, and 9.19.5 are affected by CVE-2022-38178. Additionally, some versions of ISC BIND and other software packages are also affected.
How can the CVE-2022-38178 vulnerability be fixed?
To fix the CVE-2022-38178 vulnerability, it is recommended to update to the following versions: Bind package - 9.16.44-1~deb11u1, 9.18.19-1~deb12u1, or 9.19.17-1; ISC BIND - 9.11.5.P4+dfsg-5.1+deb10u9. Check the vendor's website for official patches and updates.
Where can I find more information about CVE-2022-38178?
You can find more information about CVE-2022-38178 on the Red Hat Bugzilla pages (bugzilla.redhat.com) and the Red Hat Security Advisory (access.redhat.com/errata/RHSA-2022:6763).