#VU71749 Input validation error in ISC BIND - CVE-2022-3488
Published: February 2, 2023
ISC BIND
ISC
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of repeated responses to the same query, where both responses contain ECS pseudo-options, however the first is incorrect and gets rejected by the resolver. A remote attacker controlling a malicious nameserver can respond with two responses in
quick succession, each with a "CLIENT-SUBNET" pseudo-option and crash the server.