Skip to main content

ISC Releases Security Advisories for Multiple Versions of BIND 9

Security Updates for the Berkeley Internet Name Domain system

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Security Updates for the Berkeley Internet Name Domain system


Threat details

Introduction

The Internet Systems Consortium (ISC) has released security updates that address four High vulnerabilities in multiple versions of ISC Berkeley Internet Name Domain (BIND). An attacker could exploit these vulnerabilities to cause a denial-of-service condition.


Remediation advice

Affected organisations are encouraged to review the ISC security advisories and apply the necessary updates or workarounds.


Remediation steps

Type Step
Patch

CVE-2022-3094: An UPDATE message flood may cause named to exhaust all available memory


https://kb.isc.org/v1/docs/cve-2022-3094
Patch

CVE-2022-3488: BIND Supported Preview Edition named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries


https://kb.isc.org/v1/docs/cve-2022-3488
Patch

CVE-2022-3736: named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries


https://kb.isc.org/v1/docs/cve-2022-3736
Patch

CVE-2022-3924: named configured to answer from stale cache may terminate unexpectedly at recursive-clients soft quota


https://kb.isc.org/v1/docs/cve-2022-3924

Definitive source of threat updates


CVE Vulnerabilities

Last edited: 27 January 2023 12:33 pm