7.5

CVE-2022-38178

Memory leaks in EdDSA DNSSEC verification code

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Isc ≫ Bind Version >= 9.9.12 <= 9.9.13
Isc ≫ Bind Version >= 9.10.7 <= 9.10.8
Isc ≫ Bind Version >= 9.11.3 <= 9.16.32
Isc ≫ Bind Version 9.11.3 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.3 Update s4 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s3
Isc ≫ Bind Version 9.11.5 Update s3 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s5 SwEdition supported_preview
Isc ≫ Bind Version 9.11.5 Update s6 SwEdition supported_preview
Isc ≫ Bind Version 9.11.6 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.7 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.8 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.12 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.14-s1 SwEdition preview
Isc ≫ Bind Version 9.11.19-s1 SwEdition preview
Isc ≫ Bind Version 9.11.21 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.27 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.29 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.35 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.11.37 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.8 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.11 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.13 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.21 Update s1 SwEdition supported_preview
Isc ≫ Bind Version 9.16.32 Update s1 SwEdition supported_preview
Debian ≫ Debian Linux Version 11.0
Fedoraproject ≫ Fedora Version 35
Fedoraproject ≫ Fedora Version 36
Fedoraproject ≫ Fedora Version 37
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.51% 0.831
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ISC 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://security.gentoo.org/glsa/202210-25
Third Party Advisory
http://www.openwall.com/lists/oss-security/2022/09/21/3
Patch
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5235
Third Party Advisory
https://kb.isc.org/docs/cve-2022-38178
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20221228-0009/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/