ISC Releases Security Advisories for Multiple Versions of BIND 9
Security Updates for the Berkeley Internet Name Domain system
Summary
Security Updates for the Berkeley Internet Name Domain system
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The Internet Systems Consortium (ISC) has released security updates that address four High vulnerabilities in multiple versions of ISC Berkeley Internet Name Domain (BIND). An attacker could exploit these vulnerabilities to cause a denial-of-service condition.
Remediation advice
Affected organisations are encouraged to review the ISC security advisories and apply the necessary updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
CVE-2022-3094: An UPDATE message flood may cause named to exhaust all available memory https://kb.isc.org/v1/docs/cve-2022-3094 |
| Patch |
CVE-2022-3488: BIND Supported Preview Edition named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries https://kb.isc.org/v1/docs/cve-2022-3488 |
| Patch |
CVE-2022-3736: named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries https://kb.isc.org/v1/docs/cve-2022-3736 |
| Patch |
CVE-2022-3924: named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota https://kb.isc.org/v1/docs/cve-2022-3924 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 27 January 2023 12:33 pm