CVE-2022-38178

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/09/2022
Last modified:
28/05/2025

Description

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.9.12 (including) 9.9.13 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.10.7 (including) 9.10.8 (including)
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* 9.11.3 (including) 9.16.32 (including)
cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.3:s4:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.5:s3:*:*:*:supported_preview:*:*
cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.5:s6:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:*
cpe:2.3:a:isc:bind:9.11.14-s1:*:*:*:preview:*:*:*
cpe:2.3:a:isc:bind:9.11.19-s1:*:*:*:preview:*:*:*