• News/
  • https://www.theregister.com/2024/03/26/software_risk_scores/

Double trouble for DNSSEC though the devil is in the details

The Register
·
Thomas Claburn
·
Published Mar 26, 2024
·
Updated

Updated Two DNSSEC vulnerabilities were disclosed last month with similar descriptions and the same severity score, but they are not the same issue. One, named KeyTrap (CVE-2023-50387) by Germany’s National Research Centre for applied cybersecurity (ATHENE), was described as "one of the worst ever discovered," by Akamai exec Sven Dummer, because it could be used to disable large portions of the internet. KeyTrap allowed a single DNS packet to deny service by exhausting the CPU resources of machines running DNSSEC-validated DNS services, such as those provided by Google and Cloudflare. DNSSEC (Domain Name System Security Extensions) offers a cryptographic way to protect DNS interactions. But its implementation specification failed to account for the possibility of maliciously crafted packets that could force a responder to tie itself in knots doing obligatory calculations. The other DNSSEC flaw, NSEC3-encloser (CVE-2023-50868), was found by Petr Špaček from the Internet Systems Consortium (ISC) and was also presented as a CPU exhaustion risk. But based on an analysis conducted by the ATHENE team, it now looks largely inconsequential. Both earned a severity rating of 7.5 out of 10 under the Common Vulnerability Scoring System (CVSS) by MITRE, the nonprofit security outfit that operates US federally funded research and development centers. The two flaws were also described in advisories from the ISC, maker of affected BIND 9 DNS software, using identical terms. The CVEs for KeyT...

Read full article

Affected Software

3 affected components
Google DNSSEC-validated DNS services
Cloudflare DNSSEC-validated DNS services
ISC BIND 9
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What are the vulnerabilities discussed in the article?

The article discusses two DNSSEC vulnerabilities, one named KeyTrap (CVE-2023-50387) and another unspecified, that were disclosed last month.

2

How severe are the disclosed vulnerabilities?

Both vulnerabilities have the same severity score, but they are distinct issues.

3

Which software products are affected by these vulnerabilities?

The affected products include Google DNSSEC-validated DNS services, Cloudflare DNSSEC-validated DNS services, and ISC BIND 9.

4

What organization disclosed the KeyTrap vulnerability?

The KeyTrap vulnerability was disclosed by Germany’s National Research Centre for Applied Cybersecurity.

5

What are the potential security implications of these vulnerabilities?

The vulnerabilities could potentially expose DNSSEC users to risks such as unauthorized data manipulation or domain hijacking.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203