Back

MEDIUM

Processing large delegations may severely degrade resolver performance

Published Sep 21, 2022

Description

By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND: BIND 9.16.33, BIND 9.18.7, BIND 9.19.5, or for BIND Supported Preview Edition (a special feature preview branch of BIND provided to eligible ISC support customers): BIND 9.16.33-S1.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Sep 21, 2022
Updated Nov 29, 2024
Reserved Aug 12, 2022
CISA Vulnrichment
Updated Apr 12, 2024
NVD
Status Modified
Modified Sep 1, 2026
Red Hat
Severity Moderate
Public date Sep 21, 2022