Lucene search

K
f5F5F5:K000137229
HistoryOct 13, 2023 - 12:00 a.m.

K000137229 : BIND vulnerability CVE-2022-38178

2023-10-1300:00:00
my.f5.com
10
bind
vulnerability
cve-2022-38178
remote attacker
denial-of-service
dns resolution

6.9 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.2%

Security Advisory Description

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. (CVE-2022-38178)

Impact

DNS resolution is disrupted while the namedprocess restarts. This vulnerability allows a remote unauthenticated attacker to cause a denial-of-service (DoS) on the namedprocess.