Resource exhaustion in ISC BIND - CVE-2022-3094

 

Resource exhaustion in ISC BIND - CVE-2022-3094

Published: January 25, 2023 / Updated: February 2, 2023


Vulnerability identifier: #VU71529
CSH Severity: Medium
CVSS v4 BT: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2022-3094
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when handling DNS updates. A remote attacker can trigger resource exhaustion by sending a flood of dynamic DNS updates.


Affected software

ISC BIND
Amazon Linux AMI
Debian Linux
Oracle Linux
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
IBM i
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Oracle Solaris
Slackware Linux
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Desktop
openSUSE Leap
Ubuntu
openEuler
Fedora
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
HPE Moonshot 1500 Chassis Manager
OpenShift Pipelines
Red Hat Advanced Cluster Security for Kubernetes
Netcool Operations Insight
Ansible Automation Platform
IBM Power Hardware Management Console (HMC)
IBM Cloud Pak for Business Automation
OpenShift Virtualization
OpenShift Service Mesh
OpenShift Data Foundation (formerly OpenShift Container Storage)
Juniper Secure Analytics (JSA)
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dhcp (Red Hat package)
bind (Red Hat package) main
bind-export-devel
bind-devel
bind-chroot
bind
bind-libs
bind-libs-lite
bind-export-libs
python3-bind
bind-lite-devel
bind-pkcs11
bind-pkcs11-devel
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind-utils
bind-license
bind9 (Ubuntu package)
bind-utils-debuginfo
bind-chrootenv
libbind9-1600
libbind9-1600-debuginfo
libdns1605
libdns1605-debuginfo
libirs-devel
libirs1601
libirs1601-debuginfo
bind-doc
libns1604-debuginfo
bind-debugsource
bind-debuginfo
libisc1606
libisc1606-debuginfo
libisccc1600
libisccc1600-debuginfo
libisccfg1600
libisccfg1600-debuginfo
libns1604
bind9.16-dnssec-utils
bind9.16
bind9.16-chroot
bind9.16-devel
bind9.16-libs
bind9.16-utils
bind9.16-doc
bind9.16-license
python3-bind9.16
bind9.16 (Red Hat package)
bind-dnssec-utils
bind-dnssec-doc
bind9 (Debian package)
bind-9.16.37-1.fc36 bind-dyndb-ldap
bind-9.18.11-1.fc37 bind-dyndb-ldap
bind-9.18.11-1.fc38 bind-dyndb-ldap
Storage Virtualize
IBM Cloud Pak for Watson AIOps
Robotic Process Automation for Cloud Pak
Red Hat OpenShift GitOps
IBM Integrated Analytics System
IBM Qradar SIEM

How to mitigate CVE-2022-3094

Install updates from vendor's website.

ISC BIND - addressed in versions 9.16.37, 9.16.37-S1, 9.18.11, 9.19.9
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
OpenShift Pipelines - update to 1.10.6
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.8, 4.1.6, 4.3.1
OpenShift Virtualization - addressed in versions 4.12.9, 4.14.6
Red Hat OpenShift Container Platform - addressed in versions 4.12.57, 4.13.2, 4.13.42, 4.15.13
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
Red Hat Single Sign-On - update to 7.6.6
Storage Virtualize - addressed in versions 8.7.0.3, 8.7.2.0
Netcool Operations Insight - update to 1.6.12
Red Hat OpenShift GitOps - update to 1.12.4
Ansible Automation Platform - update to 2.4
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
dhcp (Red Hat package) - update to 4.3.6-47.el8_6.2
IBM Cloud Pak for Watson AIOps - update to 4.4.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
IBM Integrated Analytics System - update to 8.8.24.10.SP1
bind (Red Hat package) main - addressed in versions 9.11.36-3.el8_6.7, 9.11.36-11.el8_9, 9.16.23-11.el9
bind-export-devel - update to 9.11.36-11.0.1
bind-devel - update to 9.11.36-11.0.1
bind-chroot - update to 9.11.36-11.0.1
bind - update to 9.11.36-11.0.1
bind-libs - update to 9.11.36-11.0.1
bind-libs-lite - update to 9.11.36-11.0.1
bind-export-libs - update to 9.11.36-11.0.1
python3-bind - update to 9.11.36-11.0.1
bind-lite-devel - update to 9.11.36-11.0.1
bind-pkcs11 - update to 9.11.36-11.0.1
bind-pkcs11-devel - update to 9.11.36-11.0.1
bind-pkcs11-libs - update to 9.11.36-11.0.1
bind-pkcs11-utils - update to 9.11.36-11.0.1
bind-sdb - update to 9.11.36-11.0.1
bind-sdb-chroot - update to 9.11.36-11.0.1
bind-utils - update to 9.11.36-11.0.1
bind-license - update to 9.11.36-11.0.1
bind9 (Ubuntu package) - addressed in versions 1:9.16.1-0ubuntu2.12, 1:9.18.1-1ubuntu1.3, 1:9.18.4-2ubuntu2.1
bind-utils-debuginfo - addressed in versions 9.16.6-150300.22.27.1, 9.16.37-150400.5.17.1
bind-chrootenv - update to 9.16.6-150300.22.27.1
bind-devel - update to 9.16.6-150300.22.27.1
libbind9-1600 - update to 9.16.6-150300.22.27.1
libbind9-1600-debuginfo - update to 9.16.6-150300.22.27.1
libdns1605 - update to 9.16.6-150300.22.27.1
libdns1605-debuginfo - update to 9.16.6-150300.22.27.1
libirs-devel - update to 9.16.6-150300.22.27.1
libirs1601 - update to 9.16.6-150300.22.27.1
libirs1601-debuginfo - update to 9.16.6-150300.22.27.1
python3-bind - addressed in versions 9.16.6-150300.22.27.1, 9.16.37-150400.5.17.1
bind-doc - addressed in versions 9.16.6-150300.22.27.1, 9.16.37-150400.5.17.1
libns1604-debuginfo - update to 9.16.6-150300.22.27.1
bind-utils - addressed in versions 9.16.6-150300.22.27.1, 9.16.37-150400.5.17.1
bind-debugsource - addressed in versions 9.16.6-150300.22.27.1, 9.16.37-150400.5.17.1
bind-debuginfo - addressed in versions 9.16.6-150300.22.27.1, 9.16.37-150400.5.17.1
bind - addressed in versions 9.16.6-150300.22.27.1, 9.16.37-150400.5.17.1
libisc1606 - update to 9.16.6-150300.22.27.1
libisc1606-debuginfo - update to 9.16.6-150300.22.27.1
libisccc1600 - update to 9.16.6-150300.22.27.1
libisccc1600-debuginfo - update to 9.16.6-150300.22.27.1
libisccfg1600 - update to 9.16.6-150300.22.27.1
libisccfg1600-debuginfo - update to 9.16.6-150300.22.27.1
libns1604 - update to 9.16.6-150300.22.27.1
bind9.16-dnssec-utils - update to 9.16.23-0.14
bind9.16 - update to 9.16.23-0.14
bind9.16-chroot - update to 9.16.23-0.14
bind9.16-devel - update to 9.16.23-0.14
bind9.16-libs - update to 9.16.23-0.14
bind9.16-utils - update to 9.16.23-0.14
bind9.16-doc - update to 9.16.23-0.14
bind9.16-license - update to 9.16.23-0.14
python3-bind9.16 - update to 9.16.23-0.14
bind9.16 (Red Hat package) - update to 9.16.23-0.14.el8
bind-license - addressed in versions 9.16.23-14, 9.16.23-15
bind - addressed in versions 9.16.23-14, 9.16.23-15
bind-libs - addressed in versions 9.16.23-14, 9.16.23-15
bind-dnssec-utils - addressed in versions 9.16.23-14, 9.16.23-15
bind-pkcs11-devel - addressed in versions 9.16.23-14, 9.16.23-15
bind-devel - addressed in versions 9.16.23-14, 9.16.23-15
bind-pkcs11-libs - addressed in versions 9.16.23-14, 9.16.23-15
bind-debugsource - addressed in versions 9.16.23-14, 9.16.23-15
bind-chroot - addressed in versions 9.16.23-14, 9.16.23-15
bind-debuginfo - addressed in versions 9.16.23-14, 9.16.23-15
bind-pkcs11-utils - addressed in versions 9.16.23-14, 9.16.23-15
bind-utils - addressed in versions 9.16.23-14, 9.16.23-15
bind-pkcs11 - addressed in versions 9.16.23-14, 9.16.23-15
bind-dnssec-doc - addressed in versions 9.16.23-14, 9.16.23-15
python3-bind - addressed in versions 9.16.23-14, 9.16.23-15
bind - update to 9.16.37
bind9 (Debian package) - update to 1:9.16.37-1~deb11u1
bind - update to 9.16.38-1
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP2, 10.3.1060.0
bind-9.16.37-1.fc36 bind-dyndb-ldap - update to 11.9-21.fc36
bind-9.18.11-1.fc37 bind-dyndb-ldap - update to 11.10-10.fc37
bind-9.18.11-1.fc38 bind-dyndb-ldap - update to 11.10-11.fc38
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.31, 23.0.2.3
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.13, 23.0.13

External References

Related Security Bulletins