CVE-2022-3488

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure.

'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name.
This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
Affected Products (NVD)
VendorProductVersion
iscbind
9.11.4:s1
iscbind
9.11.37:s1
iscbind
9.16.8:s1
iscbind
9.16.36:s1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bind9
bookworm
1:9.18.28-1~deb12u2
fixed
bookworm (security)
1:9.18.28-1~deb12u2
fixed
bullseye
1:9.16.50-1~deb11u2
fixed
bullseye (security)
1:9.16.50-1~deb11u1
fixed
sid
1:9.20.2-1
fixed
trixie
1:9.20.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bind9
bionic
not-affected
focal
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
trusty
not-affected
xenial
not-affected
isc-dhcp
bionic
not-affected
focal
not-affected
jammy
not-affected
kinetic
not-affected
lunar
not-affected
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
bind
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-chroot
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-debugsource
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-devel
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-filesystem
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-filesystem-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-ldap
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-ldap-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-mysql
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-mysql-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-sqlite3
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dlz-sqlite3-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dnssec-doc
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dnssec-utils
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-dnssec-utils-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-libs
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-libs-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-license
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-pkcs11
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-pkcs11-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-pkcs11-devel
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-pkcs11-libs
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-pkcs11-libs-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-pkcs11-utils
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-pkcs11-utils-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-utils
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
bind-utils-debuginfo
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed
python3-bind
Amazon Linux 2023
32:9.16.38-1.amzn2023
fixed