Input validation error in ISC BIND - CVE-2022-3488

 

Input validation error in ISC BIND - CVE-2022-3488

Published: February 2, 2023


Vulnerability identifier: #VU71749
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-3488
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of repeated responses to the same query, where both responses contain ECS pseudo-options, however the first is incorrect and gets rejected by the resolver. A remote attacker controlling a malicious nameserver can respond with two responses in quick succession, each with a "CLIENT-SUBNET" pseudo-option and crash the server.


Affected software

ISC BIND
Amazon Linux AMI
IBM Spectrum Conductor
IBM Spectrum Symphony
bind

How to mitigate CVE-2022-3488

Install updates from vendor's website.

ISC BIND - update to 9.16.37-S1
IBM Spectrum Conductor - update to 2.5.1 FP2
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
bind - update to 9.16.38-1

External References

Related Security Bulletins