Search CVE reports


Toggle filters

21 – 30 of 53 results


CVE-2023-2828

Medium priority

Some fixes available 11 of 20

Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can...

3 affected packages

bind9, isc-dhcp, bind9-libs

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed Fixed
isc-dhcp Needs evaluation Not affected Not affected Needs evaluation
bind9-libs Not in release Needs evaluation Needs evaluation Not in release
Show less packages

CVE-2022-3924

Medium priority
Fixed

This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require...

2 affected packages

isc-dhcp, bind9

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-dhcp Not affected Not affected Not affected
bind9 Fixed Not affected Not affected
Show less packages

CVE-2022-38178

Medium priority
Fixed

By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

2 affected packages

bind9, isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Fixed
isc-dhcp Not affected Not affected Not affected
Show less packages

CVE-2022-38177

Medium priority
Fixed

By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.

2 affected packages

bind9, isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Not affected Fixed Fixed
isc-dhcp Not affected Not affected Not affected
Show less packages

CVE-2022-3736

Medium priority
Fixed

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12...

2 affected packages

bind9, isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Not affected Not affected
isc-dhcp Not affected Not affected Not affected
Show less packages

CVE-2022-3488

Medium priority
Not affected

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything...

2 affected packages

bind9, isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Not affected Not affected Not affected
isc-dhcp Not affected Not affected Not affected
Show less packages

CVE-2022-3094

Medium priority
Fixed

Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has...

2 affected packages

bind9, isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Fixed Not affected
isc-dhcp Not affected Not affected Not affected
Show less packages

CVE-2022-3080

Medium priority
Fixed

By sending specific queries to the resolver, an attacker can cause named to crash.

2 affected packages

bind9, isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
bind9 Fixed Not affected Not affected
isc-dhcp Not affected Not affected Not affected
Show less packages

CVE-2022-2929

Medium priority
Fixed

In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.

1 affected package

isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-dhcp Fixed Fixed Fixed
Show less packages

CVE-2022-2928

Medium priority
Fixed

In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to...

1 affected package

isc-dhcp

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
isc-dhcp Fixed Fixed Fixed
Show less packages