Summary
Processing large delegations may severely degrade resolver performance.
Overview
On September 21, 2022 ISC announced a new vulnerability, CVE-2022-2795.
A flaw in resolver code can cause named to spend excessive amounts of time on processing large delegations.
Program impacted: BIND
Severity: Medium
Exploitable: Remotely
CVSS Score: 5.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Versions
BloxOne and NIOS are vulnerable to CVE-2022-2795.
Impact
By flooding the target resolver with queries exploiting this flaw, an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.