CVE Vulnerabilities

CVE-2022-3080

Published: Sep 21, 2022 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

By sending specific queries to the resolver, an attacker can cause named to crash.

Affected Software

NameVendorStart VersionEnd Version
BindIsc9.16.14 (including)9.16.33 (excluding)
BindIsc9.18.0 (including)9.18.7 (excluding)
BindIsc9.19.0 (including)9.19.5 (excluding)
BindIsc9.16.14-s1 (including)9.16.14-s1 (including)
BindIsc9.16.21-s1 (including)9.16.21-s1 (including)
BindIsc9.16.32-s1 (including)9.16.32-s1 (including)
Red Hat Enterprise Linux 8RedHatbind9.16-32:9.16.23-0.7.el8_6.1*
Red Hat Enterprise Linux 9RedHatbind-32:9.16.23-1.el9_0.1*
Bind9Ubuntudevel*
Bind9Ubuntujammy*
Bind9Ubuntukinetic*
Bind9Ubuntutrusty*
Bind9Ubuntuxenial*

References