CVE-2022-38178
21.09.2022, 11:15
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.Enginsight
Vendor | Product | Version |
---|---|---|
isc | bind | 9.9.12 ≤ 𝑥 ≤ 9.9.13 |
isc | bind | 9.10.7 ≤ 𝑥 ≤ 9.10.8 |
isc | bind | 9.11.3 ≤ 𝑥 ≤ 9.16.32 |
isc | bind | 9.11.3:s1 |
isc | bind | 9.11.3:s4 |
isc | bind | 9.11.5:s3 |
isc | bind | 9.11.5:s3 |
isc | bind | 9.11.5:s5 |
isc | bind | 9.11.5:s6 |
isc | bind | 9.11.6:s1 |
isc | bind | 9.11.7:s1 |
isc | bind | 9.11.8:s1 |
isc | bind | 9.11.12:s1 |
isc | bind | 9.11.14-s1 |
isc | bind | 9.11.19-s1 |
isc | bind | 9.11.21:s1 |
isc | bind | 9.11.27:s1 |
isc | bind | 9.11.29:s1 |
isc | bind | 9.11.35:s1 |
isc | bind | 9.11.37:s1 |
isc | bind | 9.16.8:s1 |
isc | bind | 9.16.11:s1 |
isc | bind | 9.16.13:s1 |
isc | bind | 9.16.21:s1 |
isc | bind | 9.16.32:s1 |
debian | debian_linux | 11.0 |
netapp | active_iq_unified_manager | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
bind9 |
| ||||||||||||
isc-dhcp |
|
Common Weakness Enumeration
References