Lucene search

K
f5F5F5:K27155546
HistoryOct 19, 2022 - 12:00 a.m.

K27155546 : BIND vulnerability CVE-2022-38177

2022-10-1900:00:00
my.f5.com
14
bind
vulnerability
cve-2022-38177
memory leak
dns recursion

7.6 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

66.2%

Security Advisory Description

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources. (CVE-2022-38177)

Impact

There is no impact; F5 products are not affected by this vulnerability in default, standard, or recommended configurations. However, if the BIND configuration (named.conf) has been modified to enable DNS recursion with therecursion yes;line added to theoptionssection of your BIND configuration file, an attacker can trigger a small memory leak and erode available memory over time, causingnamed to terminate.