QID 15137
Date Published: 2023-05-29
QID 15137: ISC BIND Memory Leak Vulnerability (CVE-2022-38177)
The DNSSEC verification code for the EdDSA algorithm leaks memory when there is a signature length mismatch.
Affected versions:
BIND 9.8.4 - 9.16.32
BIND 9.9.4-S1 - 9.11.37-S1
BIND 9.16.8-S1 - 9.16.32-S1
Patched Versions:
BIND 9.16.33
BIND 9.16.33-S1
QID Detection Logic:
This unauthenticated check detects vulnerable systems by fetching the version information from the BIND service.
Successfully exploitation could affects integrity, availability, confidentiality
Solution
Customers are advised to upgrade to the patched version 9.16.33, 9.16.33-S1 or latest release of ISC BIND.
Workaround:
Disable the following algorithms in your configuration using the disable-algorithms option: ECDSAP256SHA256, ECDSAP384SHA384.
Workaround:
Disable the following algorithms in your configuration using the disable-algorithms option: ECDSAP256SHA256, ECDSAP384SHA384.
Vendor References
- CVE-2022-38177 -
kb.isc.org/v1/docs/cve-2022-38177
CVEs related to QID 15137
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2022-38177 |
|