The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the NSEC3 issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Red Hat Enterprise Linux 7 | RedHat | bind-32:9.11.4-26.P2.el7_9.16 | * |
Red Hat Enterprise Linux 7 | RedHat | bind-dyndb-ldap-0:11.1-7.el7_9.1 | * |
Red Hat Enterprise Linux 7 | RedHat | dhcp-12:4.2.5-83.el7_9.2 | * |
Red Hat Enterprise Linux 8 | RedHat | unbound-0:1.16.2-5.el8_9.2 | * |
Red Hat Enterprise Linux 8 | RedHat | dnsmasq-0:2.79-31.el8_9.2 | * |
Red Hat Enterprise Linux 8 | RedHat | bind9.16-32:9.16.23-0.16.el8_9.2 | * |
Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-11.el8_9.1 | * |
Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-14.el8_10 | * |
Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-11.el8_9.1 | * |
Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-14.el8_10 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | unbound-0:1.7.3-12.el8_2.1 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | bind-32:9.11.13-6.el8_2.7 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | dhcp-12:4.3.6-40.el8_2.3 | * |
Red Hat Enterprise Linux 8.2 Advanced Update Support | RedHat | dnsmasq-0:2.79-11.el8_2.3 | * |
Red Hat Enterprise Linux 8.2 Telecommunications Update Service | RedHat | unbound-0:1.7.3-12.el8_2.1 | * |
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | RedHat | unbound-0:1.7.3-12.el8_2.1 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | unbound-0:1.7.3-15.el8_4.1 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | bind-32:9.11.26-4.el8_4.4 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | dhcp-12:4.3.6-44.el8_4.3 | * |
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | RedHat | dnsmasq-0:2.79-15.el8_4.2 | * |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | RedHat | unbound-0:1.7.3-15.el8_4.1 | * |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | RedHat | bind-32:9.11.26-4.el8_4.4 | * |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | RedHat | dhcp-12:4.3.6-44.el8_4.3 | * |
Red Hat Enterprise Linux 8.4 Telecommunications Update Service | RedHat | dnsmasq-0:2.79-15.el8_4.2 | * |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | RedHat | unbound-0:1.7.3-15.el8_4.1 | * |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | RedHat | bind-32:9.11.26-4.el8_4.4 | * |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | RedHat | dhcp-12:4.3.6-44.el8_4.3 | * |
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | RedHat | dnsmasq-0:2.79-15.el8_4.2 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | dnsmasq-0:2.79-21.el8_6.5 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | bind9.16-32:9.16.23-0.7.el8_6.5 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | unbound-0:1.7.3-17.el8_6.4 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | bind-32:9.11.36-3.el8_6.7 | * |
Red Hat Enterprise Linux 8.6 Extended Update Support | RedHat | dhcp-12:4.3.6-47.el8_6.2 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | unbound-0:1.16.2-5.el8_8.1 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | dnsmasq-0:2.79-26.el8_8.4 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | bind9.16-32:9.16.23-0.14.el8_8.4 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | bind-32:9.11.36-8.el8_8.4 | * |
Red Hat Enterprise Linux 8.8 Extended Update Support | RedHat | dhcp-12:4.3.6-49.el8_8.1 | * |
Red Hat Enterprise Linux 9 | RedHat | unbound-0:1.16.2-3.el9_3.1 | * |
Red Hat Enterprise Linux 9 | RedHat | dnsmasq-0:2.85-14.el9_3.1 | * |
Red Hat Enterprise Linux 9 | RedHat | bind-32:9.16.23-14.el9_3.4 | * |
Red Hat Enterprise Linux 9 | RedHat | bind-dyndb-ldap-0:11.9-8.el9_3.3 | * |
Red Hat Enterprise Linux 9 | RedHat | bind-32:9.16.23-18.el9_4.1 | * |
Red Hat Enterprise Linux 9 | RedHat | bind-dyndb-ldap-0:11.9-9.el9_4 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | dnsmasq-0:2.85-3.el9_0.1 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | bind-32:9.16.23-1.el9_0.5 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | bind-dyndb-ldap-0:11.9-7.el9_0.1 | * |
Red Hat Enterprise Linux 9.0 Extended Update Support | RedHat | unbound-0:1.13.1-13.el9_0.4 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | unbound-0:1.16.2-3.el9_2.1 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | dnsmasq-0:2.85-6.el9_2.3 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | bind-32:9.16.23-11.el9_2.4 | * |
Red Hat Enterprise Linux 9.2 Extended Update Support | RedHat | bind-dyndb-ldap-0:11.9-8.el9_2.2 | * |
Bind9 | Ubuntu | bionic | * |
Bind9 | Ubuntu | devel | * |
Bind9 | Ubuntu | esm-infra/bionic | * |
Bind9 | Ubuntu | esm-infra/xenial | * |
Bind9 | Ubuntu | focal | * |
Bind9 | Ubuntu | jammy | * |
Bind9 | Ubuntu | mantic | * |
Bind9 | Ubuntu | noble | * |
Bind9 | Ubuntu | oracular | * |
Bind9 | Ubuntu | trusty | * |
Bind9 | Ubuntu | trusty/esm | * |
Bind9 | Ubuntu | upstream | * |
Bind9 | Ubuntu | xenial | * |
Dnsmasq | Ubuntu | bionic | * |
Dnsmasq | Ubuntu | devel | * |
Dnsmasq | Ubuntu | esm-infra/bionic | * |
Dnsmasq | Ubuntu | esm-infra/xenial | * |
Dnsmasq | Ubuntu | focal | * |
Dnsmasq | Ubuntu | jammy | * |
Dnsmasq | Ubuntu | mantic | * |
Dnsmasq | Ubuntu | noble | * |
Dnsmasq | Ubuntu | oracular | * |
Dnsmasq | Ubuntu | trusty | * |
Dnsmasq | Ubuntu | upstream | * |
Dnsmasq | Ubuntu | xenial | * |
Isc-dhcp | Ubuntu | mantic | * |
Knot-resolver | Ubuntu | bionic | * |
Knot-resolver | Ubuntu | esm-apps/noble | * |
Knot-resolver | Ubuntu | mantic | * |
Knot-resolver | Ubuntu | noble | * |
Knot-resolver | Ubuntu | upstream | * |
Knot-resolver | Ubuntu | xenial | * |
Pdns-recursor | Ubuntu | bionic | * |
Pdns-recursor | Ubuntu | esm-apps/noble | * |
Pdns-recursor | Ubuntu | mantic | * |
Pdns-recursor | Ubuntu | noble | * |
Pdns-recursor | Ubuntu | trusty | * |
Pdns-recursor | Ubuntu | upstream | * |
Pdns-recursor | Ubuntu | xenial | * |
Unbound | Ubuntu | bionic | * |
Unbound | Ubuntu | devel | * |
Unbound | Ubuntu | focal | * |
Unbound | Ubuntu | jammy | * |
Unbound | Ubuntu | mantic | * |
Unbound | Ubuntu | noble | * |
Unbound | Ubuntu | oracular | * |
Unbound | Ubuntu | trusty | * |
Unbound | Ubuntu | upstream | * |
Unbound | Ubuntu | xenial | * |