Corrective updates have been released for the stable branches of the DNS server BIND 9.16.33 and 9.18.7, as well as a new release of the experimental branch 9.19.5. The new versions fix vulnerabilities that may lead to denial of service.
- CVE-2022-2795 — Delegating a large volume may result in significant performance degradation, causing the server to be unable to handle requests.
- CVE-2022-2881 — Buffer overflow when reading, which could lead to data leakage or process crash.
- CVE-2022-2906 — Memory leaks in the implementation of the Diffie-Hellman algorithm using TKEY records, which may lead to gradual exhaustion of free memory in the system.
- CVE-2022-3080 — Possible crash server when resolving in the response sending settings from the outdated cache and the stale-answer-client-timeout parameter set to 0.
- CVE-2022-38177 and CVE-2022-38178 — Memory leaks in the DNSSEC verification code for ECDSA and EdDSA algorithms when the signature length is incorrectly specified.
Source: opennet.ru
