CVE-2023-4236
- EPSS 2.17%
- Veröffentlicht 20.09.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 08:34:41
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This iss...
CVE-2023-3341
- EPSS 2.65%
- Veröffentlicht 20.09.2023 13:15:11
- Zuletzt bearbeitet 02.12.2025 21:15:51
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-p...
CVE-2023-2828
- EPSS 3.78%
- Veröffentlicht 21.06.2023 17:15:47
- Zuletzt bearbeitet 21.11.2024 07:59:22
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-ca...
CVE-2023-2829
- EPSS 0.88%
- Veröffentlicht 21.06.2023 17:15:47
- Zuletzt bearbeitet 21.11.2024 07:59:22
A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. Thi...
CVE-2023-2911
- EPSS 2.45%
- Veröffentlicht 21.06.2023 17:15:47
- Zuletzt bearbeitet 21.11.2024 07:59:33
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly du...
CVE-2022-3924
- EPSS 16.12%
- Veröffentlicht 26.01.2023 21:16:03
- Zuletzt bearbeitet 31.03.2025 14:15:16
This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there wil...
CVE-2022-3736
- EPSS 48.71%
- Veröffentlicht 26.01.2023 21:15:57
- Zuletzt bearbeitet 01.04.2025 15:15:53
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 ...
CVE-2022-3488
- EPSS 19.19%
- Veröffentlicht 26.01.2023 21:15:52
- Zuletzt bearbeitet 01.04.2025 15:15:52
Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that would cause t...
CVE-2022-3094
- EPSS 13.21%
- Veröffentlicht 26.01.2023 21:15:50
- Zuletzt bearbeitet 01.04.2025 14:15:16
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated pri...
CVE-2022-2795
- EPSS 1.72%
- Veröffentlicht 21.09.2022 11:15:09
- Zuletzt bearbeitet 01.09.2026 19:44:42
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.