CVE Vulnerabilities

CVE-2022-3080

Published: Sep 21, 2022 | Modified: Jun 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

By sending specific queries to the resolver, an attacker can cause named to crash.

Affected Software

Name Vendor Start Version End Version
Bind Isc 9.16.14 (including) 9.16.33 (excluding)
Bind Isc 9.18.0 (including) 9.18.7 (excluding)
Bind Isc 9.19.0 (including) 9.19.5 (excluding)
Bind Isc 9.16.14-s1 (including) 9.16.14-s1 (including)
Bind Isc 9.16.21-s1 (including) 9.16.21-s1 (including)
Bind Isc 9.16.32-s1 (including) 9.16.32-s1 (including)
Bind9 Ubuntu devel *
Bind9 Ubuntu jammy *
Bind9 Ubuntu kinetic *
Bind9 Ubuntu trusty *
Bind9 Ubuntu xenial *
Red Hat Enterprise Linux 8 RedHat bind9.16-32:9.16.23-0.7.el8_6.1 *
Red Hat Enterprise Linux 9 RedHat bind-32:9.16.23-1.el9_0.1 *

References