Back

HIGH

Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only)

Published Sep 21, 2022

Description

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND: BIND 9.18.7 or BIND 9.19.5.

Red Hat statement

This flaw only affects versions BIND-9.18.0 and higher, whereas Red Hat ships BIND-9.16 and lower versions. Therefore, versions of BIND shipped with Red Hat Products are not affected by this flaw.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Sep 21, 2022
Updated May 28, 2025
Reserved Aug 19, 2022
CISA Vulnrichment
Updated May 28, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 21, 2022