An UPDATE message flood may cause named to exhaust all available memory
Published Jan 25, 2023
7.5
HIGHCVSS 3.1
EPSS 13.21%
Description
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited.
Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes.
If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome.
BIND 9.11 and earlier branches are also affected, but through exhaustion of internal resources rather than memory constraints. This may reduce performance but should not be a significant problem for most servers. Therefore we don't intend to address this for BIND versions prior to BIND 9.16. This issue affects BIND 9 versions 9.16.0 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.8-S1 through 9.16.36-S1.
Affected products
-
- Version 9.16.0StatusaffectedConstraints<=9.16.36
- Version 9.16.8-S1StatusaffectedConstraints<=9.16.36-S1
- Version 9.18.0StatusaffectedConstraints<=9.18.10
- Version 9.19.0StatusaffectedConstraints<=9.19.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 9.16.0 · < 9.16.37
- ≥ 9.18.0 · < 9.18.11
- ≥ 9.19.0 · < 9.19.9
- 9.16.8
- 9.16.11
- 9.16.13
- 9.16.14
- 9.16.21
- 9.16.32
- 9.16.36
No data.
Red Hat Enterprise Linux 8
bind-32:9.11.36-11.el8_9
Fixed · RHSA-2023:7177
Red Hat Enterprise Linux 8
bind-32:9.11.36-11.el8_9
Fixed · RHSA-2023:7177
Red Hat Enterprise Linux 8
bind9.16-32:9.16.23-0.14.el8
Fixed · RHSA-2023:2792
Red Hat Enterprise Linux 8.6 Extended Update Support
bind-32:9.11.36-3.el8_6.7
Fixed · RHSA-2024:2720
Red Hat Enterprise Linux 8.6 Extended Update Support
dhcp-12:4.3.6-47.el8_6.2
Fixed · RHSA-2024:2720
Red Hat Enterprise Linux 8.8 Extended Update Support
bind-32:9.11.36-8.el8_8.3
Fixed · RHSA-2024:1406
Red Hat Enterprise Linux 9
bind-32:9.16.23-11.el9
Fixed · RHSA-2023:2261
Red Hat Enterprise Linux 6
bind
Out of support scope
Red Hat Enterprise Linux 7
bind
Will not fix
Red Hat Enterprise Linux 9
dhcp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-11.el8_9 | Fixed | RHSA-2023:7177 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-11.el8_9 | Fixed | RHSA-2023:7177 |
| Red Hat Enterprise Linux 8 | bind9.16-32:9.16.23-0.14.el8 | Fixed | RHSA-2023:2792 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | bind-32:9.11.36-3.el8_6.7 | Fixed | RHSA-2024:2720 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | dhcp-12:4.3.6-47.el8_6.2 | Fixed | RHSA-2024:2720 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | bind-32:9.11.36-8.el8_8.3 | Fixed | RHSA-2024:1406 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-11.el9 | Fixed | RHSA-2023:2261 |
| Red Hat Enterprise Linux 6 | bind | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | bind | Will not fix | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.37, 9.18.11, 9.19.9, or 9.16.37-S1.
Red Hat statement
Exploitation of this vulnerability is limited to trusted clients who are permitted to make dynamic zone changes. The impact on the 'named' service is directly related to the volume of requests being sent in. The service will recover to normal once an attacker stops sending dynamic updates. While a performance impact can be triggered, it is unlikely to result in a crash.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 1, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 13.21% (0.13213) | 96.26th | v5 (v2026.06.15) |
| Jun 15, 2026 | 13.21% (0.13213) | 95.87th | v5 (v2026.06.15) |
| May 17, 2026 | 2.34% (0.02338) | 85.03th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.93% (0.00933) | 74.05th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.30% (0.03304) | 78.53th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.93% (0.00933) | 74.54th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.09% (0.00093) | 41.33th | v3 (v2023.03.01) |
| Jul 7, 2024 | 0.09% (0.00090) | 38.81th | v3 (v2023.03.01) |
| May 3, 2024 | 0.08% (0.00081) | 34.35th | v3 (v2023.03.01) |
| Feb 1, 2024 | 0.08% (0.00078) | 32.16th | v3 (v2023.03.01) |
| May 4, 2023 | 0.07% (0.00066) | 27.17th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00063) | 24.74th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Jan 26, 2023 | 0.89% (0.00885) | 27.43th | v2 (v2022.01.01) |
References (5)
- https://access.redhat.com/security/cve/CVE-2022-3094 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2164032 Issue Tracking
- https://kb.isc.org/docs/cve-2022-3094 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3094
- https://www.cve.org/CVERecord?id=CVE-2022-3094
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3094 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2164032 | Issue Tracking | |
| https://kb.isc.org/docs/cve-2022-3094 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3094 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3094 |
Change history (0)
No recorded changes yet.