SB2023071616 - Denial of service in Knot Resolver
Published: July 16, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2022-40188)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources caused by algorithmic complexity. A malicious authoritative server can return large NS sets or addresses and cause excessive CPU consumption.
Remediation
Install update from vendor's website.
References
- https://gitlab.nic.cz/knot/knot-resolver/-/merge_requests/1343#note_262558
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S2VE5K3VDUHJOIA2IGT3G5R76IBADMNE/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HIMDNIUI7GTUEKIBBYYW7OCTJQFPDNXL/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XO6LIVQS62MI5GG4OVYB5RHVZMYNHAHG/
- https://lists.debian.org/debian-lts-announce/2022/10/msg00008.html