Destroying a TLS session early causes assertion failure
Published May 19, 2022
7.5
HIGHCVSS 3.1
EPSS 6.17%
Description
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
Affected products
-
- Version Development Branch 9.19 9.19.0StatusaffectedConstraints-
- Version Open Source Branch 9.18 9.18.0 through versions before 9.18.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
No data.
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 8
bind9.16
Not affected
Red Hat Enterprise Linux 9
bind
Not affected
Red Hat Enterprise Linux 9
dhcp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind9.16 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND: BIND 9.18.3 or BIND 9.19.1.
Red Hat statement
This flaw only affects BIND 9.18.0 -> 9.18.2 and BIND 9.19.0, whereas Red Hat ships BIND-9.16 and lower versions. Therefore, versions of BIND shipped with Red Hat Products are not affected by this flaw. For RHEL-9, DHCP uses BIND 9 libraries (bind-9.11.x) for some services. Hence, DHCP shipped with RHEL-9 is also not affected.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.17% (0.06171) | 93.27th | v5 (v2026.06.15) |
| Jul 13, 2026 | 6.39% (0.06394) | 92.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 4.53% (0.04531) | 90.30th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.10% (0.00096) | 24.69th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.10% (0.00097) | 42.31th | v3 (v2023.03.01) |
| Oct 30, 2023 | 0.09% (0.00094) | 39.44th | v3 (v2023.03.01) |
| Jun 21, 2023 | 0.08% (0.00085) | 34.79th | v3 (v2023.03.01) |
| May 26, 2023 | 0.07% (0.00075) | 30.77th | v3 (v2023.03.01) |
| Apr 19, 2023 | 0.05% (0.00053) | 19.02th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00044) | 10.99th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Nov 10, 2022 | 0.89% (0.00885) | 26.90th | v2 (v2022.01.01) |
| May 20, 2022 | 0.89% (0.00885) | 24.87th | v2 (v2022.01.01) |
References (6)
- https://access.redhat.com/security/cve/CVE-2022-1183 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2087575 Issue Tracking
- https://kb.isc.org/docs/cve-2022-1183 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1183
- https://security.netapp.com/advisory/ntap-20220707-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1183
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-1183 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2087575 | Issue Tracking | |
| https://kb.isc.org/docs/cve-2022-1183 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-1183 | ||
| https://security.netapp.com/advisory/ntap-20220707-0002/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-1183 |
Change history (0)
No recorded changes yet.