named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries
Published Jan 25, 2023
7.5
HIGHCVSS 3.1
EPSS 19.19%
Description
Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure.
'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.
Affected products
-
- Version 9.11.4-S1StatusaffectedConstraints<=9.11.37-S1
- Version 9.16.8-S1StatusaffectedConstraints<=9.16.36-S1
- Version
No data.
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 8
bind9.16
Not affected
Red Hat Enterprise Linux 9
bind
Not affected
Red Hat Enterprise Linux 9
dhcp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind9.16 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | dhcp | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.37-S1.
Red Hat statement
This issue only affects the special feature preview branch of bind. Bind packages shipped with Red Hat Enterprise Linux are not affected by this flaw.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Apr 1, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (21 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 19.19% (0.19193) | 97.25th | v5 (v2026.06.15) |
| Jun 15, 2026 | 19.05% (0.19045) | 96.94th | v5 (v2026.06.15) |
| Apr 22, 2026 | 15.21% (0.15211) | 94.64th | v4 (v2025.03.14) |
| Apr 6, 2026 | 13.86% (0.13857) | 94.27th | v4 (v2025.03.14) |
| Mar 26, 2026 | 12.19% (0.12192) | 93.78th | v4 (v2025.03.14) |
| Mar 17, 2026 | 13.30% (0.13300) | 94.07th | v4 (v2025.03.14) |
| Jan 28, 2026 | 11.69% (0.11690) | 93.49th | v4 (v2025.03.14) |
| Nov 21, 2025 | 9.69% (0.09690) | 92.60th | v4 (v2025.03.14) |
| Nov 18, 2025 | 0.28% (0.00284) | 48.80th | v4 (v2025.03.14) |
| Sep 14, 2025 | 7.97% (0.07969) | 91.74th | v4 (v2025.03.14) |
| Mar 30, 2025 | 10.10% (0.10101) | 92.36th | v4 (v2025.03.14) |
| Mar 29, 2025 | 17.56% (0.17562) | 91.89th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.10% (0.10101) | 92.52th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.13% (0.00132) | 49.91th | v3 (v2023.03.01) |
| Jul 7, 2024 | 0.13% (0.00128) | 47.89th | v3 (v2023.03.01) |
| Feb 27, 2024 | 0.11% (0.00115) | 44.19th | v3 (v2023.03.01) |
| Feb 1, 2024 | 0.11% (0.00107) | 43.28th | v3 (v2023.03.01) |
| Dec 26, 2023 | 0.07% (0.00075) | 31.25th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00063) | 25.31th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Jan 26, 2023 | 0.89% (0.00885) | 27.43th | v2 (v2022.01.01) |
References (6)
- https://access.redhat.com/security/cve/CVE-2022-3488 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2164709 Issue Tracking
- https://kb.isc.org/docs/cve-2019-6468
- https://kb.isc.org/docs/cve-2022-3488 vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3488
- https://www.cve.org/CVERecord?id=CVE-2022-3488
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-3488 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2164709 | Issue Tracking | |
| https://kb.isc.org/docs/cve-2019-6468 | ||
| https://kb.isc.org/docs/cve-2022-3488 | vendor-advisoryVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3488 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3488 |
Change history (0)
No recorded changes yet.