Memory leaks exist in EdDSA and ECDSA DNSSEC verification code.
Overview
On September 21, 2022 ISC announced two new vulnerabilities, CVE-2022-38177 and 38178.
The DNSSEC verification code for the ECDSA algorithm leaks memory when there is a signature length mismatch.
Program impacted: BIND
Severity: High
Exploitable: Remotely
CVSS Score: 7.5
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions
BloxOne and NIOS are vulnerable to CVE-2022-38177 and CVE-2022-38178.
Impact
By spoofing the target resolver with responses that have a malformed ECDSA or EDDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.