Memory leak in ISC BIND - CVE-2022-38177

 

Memory leak in ISC BIND - CVE-2022-38177

Published: September 21, 2022 / Updated: October 20, 2022


Vulnerability identifier: #VU67549
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-38177
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak in the DNSSEC verification code for the ECDSA algorithm. A remote attacker can spoof the target resolver with responses that have a malformed ECDSA signature and perform denial of service attack.


Affected software

ISC BIND
Amazon Linux AMI
Gentoo Linux
Debian Linux
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
CentOS
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Oracle Linux
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
SUSE Linux Enterprise Storage
IBM AIX
IBM i
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Oracle Solaris
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Software Development Kit
Ubuntu
Slackware Linux
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
Fedora
IBM Integrated Analytics System
IBM QRadar Network Packet Capture
Red Hat Advanced Cluster Management for Kubernetes
Dell Secure Connect Gateway
IBM VIOS
Red Hat OpenShift Container Platform
HPE Moonshot 1500 Chassis Manager
OpenShift Virtualization
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
redhat-virtualization-host-productimg (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
bind-utils-debuginfo
bind-utils
bind-libs-debuginfo
bind-libs-debuginfo-32bit
bind-libs
bind-libs-32bit
bind-debugsource
bind-debuginfo
bind-doc
bind
bind-chrootenv
bind9 (Ubuntu package)
bind-license
bind-pkcs11-libs
bind-pkcs11-devel
bind-pkcs11
bind-lite-devel
bind-libs-lite
bind-export-libs
bind-export-devel
bind-devel
bind-chroot
bind-pkcs11-utils
bind-sdb-chroot
bind-sdb
bind (Red Hat package) main
python3-bind
libirs161
libisccfg163
libisccc161-debuginfo
libisccc161
libisc1107-debuginfo
libisc1107-debuginfo-32bit
libisc1107
liblwres161-debuginfo
liblwres161
libisccfg163-debuginfo
python-bind
libisc1107-32bit
libirs161-debuginfo
libbind9-161
libbind9-161-debuginfo
libdns1110
libdns1110-debuginfo
libisccfg1600-32bit
libdns1605
libbind9-1600-debuginfo
libbind9-1600
libns1604-32bit-debuginfo
libisccfg1600-32bit-debuginfo
libns1604-32bit
libisccc1600-32bit-debuginfo
libisccc1600-32bit
libisc1606-32bit-debuginfo
libisc1606-32bit
libirs1601-32bit-debuginfo
bind-devel-32bit
libirs1601-32bit
libdns1605-32bit-debuginfo
libdns1605-32bit
libbind9-1600-32bit-debuginfo
libbind9-1600-32bit
libirs-devel
libdns1605-debuginfo
libns1604-debuginfo
libns1604
libisccfg1600-debuginfo
libisccfg1600
libisccc1600
libisc1606-debuginfo
libisccc1600-debuginfo
libisc1606
libirs1601-debuginfo
libirs1601
bind9.16
python3-bind9.16
bind9.16-license
bind9.16-doc
bind9.16-utils
bind9.16-chroot
bind9.16-dnssec-utils
bind9.16-libs
bind9.16 (Red Hat package)
bind-dnssec-doc
bind-dnssec-utils
net-dns/bind-tools
net-dns/bind
bind9 (Debian package)
bind-dyndb-ldap
HP-UX BIND
PowerStore T
IBM Cloud Pak for Watson AIOps
EMC ECS
Robotic Process Automation for Cloud Pak
EMC ViPR SRM
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC VxRail Appliance

How to mitigate CVE-2022-38177

Install updates from vendor's website.

ISC BIND - addressed in versions 9.16.33, 9.16.33-S1
IBM Integrated Analytics System - update to 7.9.22.10.SP14
Red Hat Advanced Cluster Management for Kubernetes - update to 2.4.8
Red Hat OpenShift Container Platform - addressed in versions 4.9.50, 4.11.45, 4.13.0
OpenShift Virtualization - addressed in versions 4.9.7, 4.11.1
Dell Secure Connect Gateway - update to 5.16
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 8, 7.5.0 Update Pack 4
HP-UX BIND - update to C.9.11.1.6.0
PowerStore T - update to 3.5.0.1-2083289
IBM Cloud Pak for Watson AIOps - update to 3.6.1
EMC ECS - update to 3.8.0.2
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
redhat-virtualization-host-productimg (Red Hat package) - update to 4.5.3-1.el8
redhat-release-virtualization-host (Red Hat package) - update to 4.5.3-1.el8ev
EMC ViPR SRM - update to 4.8.0.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.1
Dell EMC VxRail Appliance - update to 7.0.411
IBM QRadar Network Packet Capture - addressed in versions 7.4.3 Fix Pack 6, 7.5.0 Update Package 3
bind-utils-debuginfo - addressed in versions 9.9.9P1-63.37.1, 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2, 9.16.33-150400.5.11.1
bind-utils - addressed in versions 9.9.9P1-63.37.1, 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2, 9.16.33-150400.5.11.1
bind-libs-debuginfo - update to 9.9.9P1-63.37.1
bind-libs-debuginfo-32bit - update to 9.9.9P1-63.37.1
bind-libs - update to 9.9.9P1-63.37.1
bind-libs-32bit - update to 9.9.9P1-63.37.1
bind-debugsource - addressed in versions 9.9.9P1-63.37.1, 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2, 9.16.33-150400.5.11.1
bind-debuginfo - addressed in versions 9.9.9P1-63.37.1, 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2, 9.16.33-150400.5.11.1
bind-doc - addressed in versions 9.9.9P1-63.37.1, 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2, 9.16.33-150400.5.11.1
bind - addressed in versions 9.9.9P1-63.37.1, 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2, 9.16.33-150400.5.11.1
bind-chrootenv - addressed in versions 9.9.9P1-63.37.1, 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
bind9 (Ubuntu package) - addressed in versions 1:9.10.3.dfsg.P48ubuntu1.19+esm3, 1:9.11.3+dfsg-1ubuntu1.18, 1:9.16.1-0ubuntu2.11, 1:9.18.1-1ubuntu1.2
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-3
bind (Red Hat package) main - addressed in versions 9.11.4-26.P2.el7_9.10, 9.11.4-26.P2.el8_1.6, 9.11.13-6.el8_2.4, 9.11.26-4.el8_4.1, 9.11.36-3.el8_6.1, 9.16.23-1.el9_0.1
python3-bind - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-devel - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-debugsource - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-export-devel - addressed in versions 9.11.21-14, 9.11.21-15
bind-libs-lite - addressed in versions 9.11.21-14, 9.11.21-15
bind-chroot - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-pkcs11-devel - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-export-libs - addressed in versions 9.11.21-14, 9.11.21-15
bind-pkcs11 - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-debuginfo - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-libs - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind-utils - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
bind - addressed in versions 9.11.21-14, 9.11.21-15, 9.16.23-11
libirs161 - update to 9.11.22-3.43.1
libisccfg163 - update to 9.11.22-3.43.1
libisccc161-debuginfo - update to 9.11.22-3.43.1
libisccc161 - update to 9.11.22-3.43.1
libisc1107-debuginfo - update to 9.11.22-3.43.1
libisc1107-debuginfo-32bit - update to 9.11.22-3.43.1
libisc1107 - update to 9.11.22-3.43.1
bind-devel - addressed in versions 9.11.22-3.43.1, 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
liblwres161-debuginfo - update to 9.11.22-3.43.1
liblwres161 - update to 9.11.22-3.43.1
libisccfg163-debuginfo - update to 9.11.22-3.43.1
python-bind - update to 9.11.22-3.43.1
libisc1107-32bit - update to 9.11.22-3.43.1
libirs161-debuginfo - update to 9.11.22-3.43.1
libbind9-161 - update to 9.11.22-3.43.1
libbind9-161-debuginfo - update to 9.11.22-3.43.1
libdns1110 - update to 9.11.22-3.43.1
libdns1110-debuginfo - update to 9.11.22-3.43.1
python3-bind - update to 9.11.36-3
libisccfg1600-32bit - update to 9.16.6-150000.12.63.1
libdns1605 - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libbind9-1600 - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libns1604-32bit-debuginfo - update to 9.16.6-150000.12.63.1
libisccfg1600-32bit-debuginfo - update to 9.16.6-150000.12.63.1
libns1604-32bit - update to 9.16.6-150000.12.63.1
libisccc1600-32bit-debuginfo - update to 9.16.6-150000.12.63.1
libisccc1600-32bit - update to 9.16.6-150000.12.63.1
libisc1606-32bit-debuginfo - update to 9.16.6-150000.12.63.1
libisc1606-32bit - update to 9.16.6-150000.12.63.1
libirs1601-32bit-debuginfo - update to 9.16.6-150000.12.63.1
bind-devel-32bit - update to 9.16.6-150000.12.63.1
libirs1601-32bit - update to 9.16.6-150000.12.63.1
libdns1605-32bit-debuginfo - update to 9.16.6-150000.12.63.1
libdns1605-32bit - update to 9.16.6-150000.12.63.1
libbind9-1600-32bit-debuginfo - update to 9.16.6-150000.12.63.1
libbind9-1600-32bit - update to 9.16.6-150000.12.63.1
libirs-devel - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
python3-bind - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2, 9.16.33-150400.5.11.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libns1604 - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libisccfg1600 - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libisccc1600 - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libisc1606 - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
libirs1601 - addressed in versions 9.16.6-150000.12.63.1, 9.16.6-150300.22.21.2
bind9.16 - update to 9.16.23-0.7
python3-bind9.16 - update to 9.16.23-0.7
bind9.16-license - update to 9.16.23-0.7
bind9.16-doc - update to 9.16.23-0.7
bind9.16-utils - update to 9.16.23-0.7
bind9.16-chroot - update to 9.16.23-0.7
bind9.16-dnssec-utils - update to 9.16.23-0.7
bind9.16-libs - update to 9.16.23-0.7
bind9.16 (Red Hat package) - addressed in versions 9.16.23-0.7.el8_6.1, 9.16.23-0.9.el8.1
bind-dnssec-doc - update to 9.16.23-11
bind-pkcs11-libs - update to 9.16.23-11
bind-dnssec-utils - update to 9.16.23-11
bind-pkcs11-utils - update to 9.16.23-11
bind-license - update to 9.16.23-11
bind - update to 9.16.33
net-dns/bind-tools - update to 9.16.33
net-dns/bind - update to 9.16.33
bind - addressed in versions 9.16.33-1.fc35, 9.16.33-1.fc36, 9.18.7-1.fc37, 9.18.7-1.fc38
bind9 (Debian package) - update to 1:9.16.33-1~deb11u1
bind - update to 9.16.38-1
bind-dyndb-ldap - addressed in versions 11.9-16.fc35, 11.9-20.fc36, 11.10-6.fc37, 11.10-6.fc38
Robotic Process Automation for Cloud Pak - update to 21.0.6

External References

Related Security Bulletins