Input validation error in ISC BIND - CVE-2022-3488
Published: February 2, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of repeated responses to the same query, where both responses contain ECS pseudo-options, however the first is incorrect and gets rejected by the resolver. A remote attacker controlling a malicious nameserver can respond with two responses in
quick succession, each with a "CLIENT-SUBNET" pseudo-option and crash the server.
Affected software
Amazon Linux AMI
IBM Spectrum Conductor
IBM Spectrum Symphony
bind
How to mitigate CVE-2022-3488
IBM Spectrum Conductor - update to 2.5.1 FP2
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
bind - update to 9.16.38-1