Out-of-bounds read in ISC BIND - CVE-2022-2881
Published: September 21, 2022 / Updated: October 20, 2022
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when reusing HTTP connection while requesting statistics from the stats channel. A remote DNS server under attacker's control trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service attack.
Affected software
Gentoo Linux
Oracle Solaris
Ubuntu
openEuler
HPE Moonshot 1500 Chassis Manager
bind9 (Ubuntu package)
bind-export-libs
python3-bind
bind-debugsource
bind-export-devel
bind-libs-lite
bind-chroot
bind-devel
bind-pkcs11-devel
bind-pkcs11
bind-debuginfo
bind-libs
bind-utils
bind
bind-license
bind-pkcs11-libs
bind-dnssec-utils
bind-pkcs11-utils
bind-dnssec-doc
net-dns/bind
net-dns/bind-tools
How to mitigate CVE-2022-2881
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
bind9 (Ubuntu package) - addressed in versions 1:9.11.3+dfsg-1ubuntu1.18, 1:9.16.1-0ubuntu2.11, 1:9.18.1-1ubuntu1.2
bind-export-libs - addressed in versions 9.11.21-14, 9.11.21-15
python3-bind - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-debugsource - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-export-devel - addressed in versions 9.11.21-14, 9.11.21-15
bind-libs-lite - addressed in versions 9.11.21-14, 9.11.21-15
bind-chroot - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-devel - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-pkcs11-devel - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-pkcs11 - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-debuginfo - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-libs - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-utils - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-license - update to 9.16.23-11
bind-pkcs11-libs - update to 9.16.23-11
bind-dnssec-utils - update to 9.16.23-11
bind-pkcs11-utils - update to 9.16.23-11
bind-dnssec-doc - update to 9.16.23-11
net-dns/bind - update to 9.16.33
net-dns/bind-tools - update to 9.16.33
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC Bind
- Ubuntu update for bind9
- Oracle Solaris update for third-party software
- Gentoo update for ISC BIND
- openEuler 20.03 LTS SP1 update for bind
- openEuler 20.03 LTS SP3 update for bind
- openEuler 22.03 LTS update for bind
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager