CVE-2022-3094
Last modified
CVE-2022-3094 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. EPSS estimates a 13.11% chance of exploitation in the next 30 days.
Description
Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client whose access credentials are accepted. Memory allocated to clients that are not permitted to send updates is released immediately upon rejection. The scope of this vulnerability is limited therefore to trusted clients who are permitted to make dynamic zone changes. If a dynamic update is REFUSED, memory will be released again very quickly. Therefore it is only likely to be possible to degrade or stop `named` by sending a flood of unaccepted dynamic updates comparable in magnitude to a query flood intended to achieve the same detrimental outcome. BIND 9.11 and earlier branches are also affected, but through exhaustion of internal resources rather than memory constraints. This may reduce performance but should not be a significant problem for most servers. Therefore we don't intend to address this for BIND versions prior to BIND 9.16. This issue affects BIND 9 versions 9.16.0 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.8-S1 through 9.16.36-S1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Isc | Bind | >= 9.16.0, < 9.16.37 | — |
| Isc | Bind | >= 9.18.0, < 9.18.11 | — |
| Isc | Bind | >= 9.19.0, < 9.19.9 | — |
| Isc | Bind | 9.16.8 | S1 |
| Isc | Bind | 9.16.11 | S1 |
| Isc | Bind | 9.16.13 | S1 |
| Isc | Bind | 9.16.14 | S1 |
| Isc | Bind | 9.16.21 | S1 |
| Isc | Bind | 9.16.32 | S1 |
| Isc | Bind | 9.16.36 | S1 |
References
- https://kb.isc.org/docs/cve-2022-3094Vendor Advisory
- https://kb.isc.org/docs/cve-2022-3094Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-3094?
How severe is CVE-2022-3094?
How do I fix CVE-2022-3094?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-30930Tourism Management System Version: V 3.2 is affected by: Cro…4.3
- CVE-2022-30931Employee Leaves Management System (ELMS) V 2.1 is vulnerable…6.5
- CVE-2022-30932Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-30935An authorization bypass in b2evolution allows remote, unauth…9.1
- CVE-2022-30937A vulnerability has been identified in EN100 Ethernet module…7.5
- CVE-2022-30938A vulnerability has been identified in EN100 Ethernet module…7.5
- CVE-2022-30943Browsing restriction bypass vulnerability in Bulletin of Cyb…4.3
- CVE-2022-30944Insufficiently protected credentials for Intel(R) AMT and In…5.5
- CVE-2022-30945Jenkins Pipeline: Groovy Plugin 2689.v434009a_31b_f1 and ear…8.5
- CVE-2022-30946A cross-site request forgery (CSRF) vulnerability in Jenkins…4.3
- CVE-2022-30947Jenkins Git Plugin 4.11.1 and earlier allows attackers able …7.5
- CVE-2022-30948Jenkins Mercurial Plugin 2.16 and earlier allows attackers a…7.5
Are you affected by CVE-2022-3094?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
