Back

HIGH

Buffer overread in statistics channel code

Published Sep 21, 2022

Description

The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND: BIND 9.18.7 or BIND 9.19.5.

Red Hat statement

This flaw only affects versions BIND-9.18.0 and higher, whereas Red Hat ships BIND-9.16 and lower versions. Therefore, versions of BIND shipped with Red Hat Products are not affected by this flaw.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Sep 21, 2022
Updated May 28, 2025
Reserved Aug 17, 2022
CISA Vulnrichment
Updated May 28, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 21, 2022