First published: Fri Sep 23 2022(Updated: )
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nic Knot Resolver | <5.5.3 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 | |
Debian Debian Linux | =10.0 | |
ubuntu/knot-resolver | <5.5.1-5ubuntu0.22.10.1 | 5.5.1-5ubuntu0.22.10.1 |
ubuntu/knot-resolver | <5.5.3-1 | 5.5.3-1 |
ubuntu/knot-resolver | <2.1.1-1ubuntu0.1~ | 2.1.1-1ubuntu0.1~ |
ubuntu/knot-resolver | <3.2.1-3ubuntu2.1 | 3.2.1-3ubuntu2.1 |
ubuntu/knot-resolver | <5.4.4-1ubuntu0.1~ | 5.4.4-1ubuntu0.1~ |
ubuntu/knot-resolver | <1.0.0~ | 1.0.0~ |
debian/knot-resolver | <=3.2.1-3<=5.3.1-1+deb11u1 | 3.2.1-3+deb10u1 5.6.0-1 5.7.0-1 |
<5.5.3 | ||
=35 | ||
=36 | ||
=37 | ||
=10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40188 is a vulnerability in Knot Resolver before version 5.5.3 that allows remote attackers to cause a denial of service (CPU consumption) due to algorithmic complexity.
CVE-2022-40188 has a severity rating of 7.5 (high).
Knot Resolver versions up to and including 5.5.1-5ubuntu0.22.10.1, 5.5.3-1, 2.1.1-1ubuntu0.1~, 3.2.1-3ubuntu2.1, 5.4.4-1ubuntu0.1~, and 1.0.0~ are affected.
To fix CVE-2022-40188, update Knot Resolver to version 5.5.3 or higher.
The Common Weakness Enumeration (CWE) ID for CVE-2022-40188 is CWE-407.