CVE-2023-50868

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Debian logo
Debian Releases
Debian Product
Codename
bind9
bullseye
1:9.16.50-1~deb11u2
no-dsa
bookworm
1:9.18.28-1~deb12u2
no-dsa
buster
no-dsa
bullseye (security)
1:9.16.50-1~deb11u1
fixed
bookworm (security)
1:9.18.28-1~deb12u2
fixed
sid
1:9.20.4-3
fixed
trixie
1:9.20.4-3
fixed
dnsjava
sid
vulnerable
bookworm
no-dsa
bullseye
no-dsa
buster
no-dsa
dnsmasq
bullseye
no-dsa
bookworm
no-dsa
buster
no-dsa
bullseye (security)
2.85-1+deb11u1
fixed
sid
2.90-7
fixed
trixie
2.90-7
fixed
knot-resolver
bullseye
no-dsa
bookworm
5.6.0-1+deb12u1
no-dsa
buster
no-dsa
bookworm (security)
5.6.0-1+deb12u1
fixed
sid
5.7.4-2
fixed
trixie
5.7.4-2
fixed
pdns-recursor
bullseye
no-dsa
bookworm
4.8.8-1
no-dsa
buster
no-dsa
bookworm (security)
4.8.8-1
fixed
sid
5.1.3-1
fixed
trixie
5.1.3-1
fixed
systemd
bullseye
no-dsa
bookworm
252.31-1~deb12u1
no-dsa
buster
no-dsa
bullseye (security)
247.3-7+deb11u6
fixed
trixie
257.1-4
fixed
sid
257.1-5
fixed
unbound
bullseye
1.13.1-1+deb11u2
no-dsa
bookworm
1.17.1-2+deb12u2
no-dsa
buster
no-dsa
bullseye (security)
1.13.1-1+deb11u4
fixed
bookworm (security)
1.17.1-2+deb12u2
fixed
sid
1.22.0-1
fixed
trixie
1.22.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bind9
oracular
Fixed 1:9.18.24-0ubuntu1
released
noble
Fixed 1:9.18.24-0ubuntu1
released
mantic
Fixed 1:9.18.18-0ubuntu2.1
released
jammy
Fixed 1:9.18.18-0ubuntu0.22.04.2
released
focal
Fixed 1:9.16.48-0ubuntu0.20.04.1
released
bionic
Fixed 1:9.11.3+dfsg-1ubuntu1.19+esm3
released
xenial
Fixed 1:9.10.3.dfsg.P4-8ubuntu1.19+esm8
released
trusty
Fixed 1:9.9.5.dfsg-3ubuntu0.19+esm12
released
bind9-libs
oracular
dne
noble
dne
mantic
dne
jammy
needs-triage
focal
needs-triage
bionic
dne
xenial
dne
trusty
dne
dnsmasq
oracular
Fixed 2.90-1
released
noble
Fixed 2.90-1
released
mantic
Fixed 2.90-0ubuntu0.23.10.1
released
jammy
Fixed 2.90-0ubuntu0.22.04.1
released
focal
Fixed 2.90-0ubuntu0.20.04.1
released
bionic
Fixed 2.90-0ubuntu0.18.04.1+esm1
released
xenial
Fixed 2.90-0ubuntu0.16.04.1+esm1
released
trusty
ignored
isc-dhcp
oracular
needs-triage
noble
needs-triage
mantic
ignored
jammy
not-affected
focal
not-affected
bionic
needs-triage
xenial
not-affected
trusty
not-affected
knot-resolver
oracular
not-affected
noble
pending
mantic
ignored
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
dne
pdns-recursor
oracular
not-affected
noble
pending
mantic
ignored
jammy
needs-triage
focal
needs-triage
bionic
needs-triage
xenial
needs-triage
trusty
ignored
unbound
oracular
Fixed 1.19.1-1ubuntu1
released
noble
Fixed 1.19.1-1ubuntu1
released
mantic
Fixed 1.17.1-2ubuntu0.1
released
jammy
Fixed 1.13.1-1ubuntu5.4
released
focal
Fixed 1.9.4-2ubuntu1.5
released
bionic
needs-triage
xenial
needs-triage
trusty
ignored
References