imPC@ndo IT

Tracker / CVE-2023-50387

CVE-2023-50387

High 7.5

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

Affected products and versions

fedoraproject fedora
isc bind · 9.0.0 → 9.16.46
isc bind · 9.18.0 → 9.18.22
isc bind · 9.19.0 → 9.19.20
microsoft windows_server_2008
microsoft windows_server_2012
microsoft windows_server_2016
microsoft windows_server_2019
microsoft windows_server_2022
microsoft windows_server_2022_23h2
nic knot_resolver · … → 5.71
nlnetlabs unbound · … → 1.19.1
powerdns recursor · 4.8.0 → 4.8.6
powerdns recursor · 4.9.0 → 4.9.3
powerdns recursor · 5.0.0 → 5.0.2
redhat enterprise_linux
thekelleys dnsmasq · … → 2.90

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References