CVE Vulnerabilities

CVE-2022-40188

Inefficient Algorithmic Complexity

Published: Sep 23, 2022 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.

Weakness

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

Affected Software

Name Vendor Start Version End Version
Knot_resolver Nic * 5.5.3 (excluding)
Knot-resolver Ubuntu bionic *
Knot-resolver Ubuntu esm-apps/bionic *
Knot-resolver Ubuntu esm-apps/jammy *
Knot-resolver Ubuntu esm-apps/xenial *
Knot-resolver Ubuntu focal *
Knot-resolver Ubuntu jammy *
Knot-resolver Ubuntu kinetic *
Knot-resolver Ubuntu trusty *
Knot-resolver Ubuntu upstream *
Knot-resolver Ubuntu xenial *

References