CVE Vulnerabilities

CVE-2022-40188

Inefficient Algorithmic Complexity

Published: Sep 23, 2022 | Modified: May 27, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.

Weakness

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Software

NameVendorStart VersionEnd Version
Knot_resolverNic*5.5.3 (excluding)
Knot-resolverUbuntubionic*
Knot-resolverUbuntuesm-apps/bionic*
Knot-resolverUbuntuesm-apps/focal*
Knot-resolverUbuntuesm-apps/jammy*
Knot-resolverUbuntuesm-apps/xenial*
Knot-resolverUbuntufocal*
Knot-resolverUbuntujammy*
Knot-resolverUbuntukinetic*
Knot-resolverUbuntutrusty*
Knot-resolverUbuntuupstream*
Knot-resolverUbuntuxenial*

References