CVE-2022-38178: Memory leaks in EdDSA DNSSEC verification code
A flaw was found in the Bind package, where the DNSSEC verification code for the EdDSA algorithm leaks memory when there is a signature length mismatch. By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak, resulting in crashing the program.
Other sources
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Memory leaks in EdDSA DNSSEC verification code
— Microsoft
Affected Software
Remediation
Patch Available
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-38178?
CVE-2022-38178 is a vulnerability in the Bind package that allows an attacker to trigger a small memory leak by spoofing the target resolver with responses that have a malformed EdDSA signature.
What is the severity of CVE-2022-38178?
CVE-2022-38178 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2022-38178?
The Bind package versions 9.16.33, 9.18.7, and 9.19.5 are affected by CVE-2022-38178. Additionally, some versions of ISC BIND and other software packages are also affected.
How can the CVE-2022-38178 vulnerability be fixed?
To fix the CVE-2022-38178 vulnerability, it is recommended to update to the following versions: Bind package - 9.16.44-1~deb11u1, 9.18.19-1~deb12u1, or 9.19.17-1; ISC BIND - 9.11.5.P4+dfsg-5.1+deb10u9. Check the vendor's website for official patches and updates.
Where can I find more information about CVE-2022-38178?
You can find more information about CVE-2022-38178 on the Red Hat Bugzilla pages (bugzilla.redhat.com) and the Red Hat Security Advisory (access.redhat.com/errata/RHSA-2022:6763).