CVE-2023-50387
Last modified
CVE-2023-50387 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.. EPSS estimates a 100.00% chance of exploitation in the next 30 days.
Description
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Metrics
100.0th percentile
Probability of exploitation in the next 30 days. Learn more
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Enterprise Linux | 6.0 | — |
| Redhat | Enterprise Linux | 7.0 | — |
| Redhat | Enterprise Linux | 8.0 | — |
| Redhat | Enterprise Linux | 9.0 | — |
| Microsoft | Windows Server 2008 | r2 | Sp1 |
| Microsoft | Windows Server 2012 | All versions | — |
| Microsoft | Windows Server 2012 | r2 | — |
| Microsoft | Windows Server 2016 | All versions | — |
| Microsoft | Windows Server 2019 | All versions | — |
| Microsoft | Windows Server 2022 | All versions | — |
| Microsoft | Windows Server 2022 23h2 | All versions | — |
| Fedoraproject | Fedora | 39 | — |
| Thekelleys | Dnsmasq | < 2.90 | — |
| Nic | Knot Resolver | < 5.71 | — |
| Powerdns | Recursor | >= 4.8.0, < 4.8.6 | — |
| Powerdns | Recursor | >= 4.9.0, < 4.9.3 | — |
| Powerdns | Recursor | >= 5.0.0, < 5.0.2 | — |
| Isc | Bind | >= 9.0.0, <= 9.16.46 | — |
| Isc | Bind | >= 9.18.0, <= 9.18.22 | — |
| Isc | Bind | >= 9.19.0, <= 9.19.20 | — |
| Nlnetlabs | Unbound | < 1.19.1 | — |
References
- https://access.redhat.com/security/cve/CVE-2023-50387Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1219823Issue Tracking
- https://kb.isc.org/docs/cve-2023-50387Third Party Advisory, VDB Entry
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.htmlMailing List, Third Party Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387Patch, Vendor Advisory
- https://news.ycombinator.com/item?id=39367411Third Party Advisory
- https://news.ycombinator.com/item?id=39372384Issue Tracking
- https://www.athene-center.de/aktuelles/key-trapThird Party Advisory
- https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdfTechnical Description, Third Party Advisory
- https://www.isc.org/blogs/2024-bind-security-release/Third Party Advisory
- https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/Press/Media Coverage, Third Party Advisory
- https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/Patch, Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-50387Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1219823Issue Tracking
- https://kb.isc.org/docs/cve-2023-50387Third Party Advisory, VDB Entry
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.htmlMailing List, Third Party Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387Patch, Vendor Advisory
- https://news.ycombinator.com/item?id=39367411Third Party Advisory
- https://news.ycombinator.com/item?id=39372384Issue Tracking
- https://www.athene-center.de/aktuelles/key-trapThird Party Advisory
- https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdfTechnical Description, Third Party Advisory
- https://www.isc.org/blogs/2024-bind-security-release/Third Party Advisory
- https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/Press/Media Coverage, Third Party Advisory
- https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-50387?
How severe is CVE-2023-50387?
How do I fix CVE-2023-50387?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-5038badmonkey, a Security Researcher has found a flaw that allow…7.5
- CVE-2023-50380XML External Entity injection in apache ambari versions <= 2…6.5
- CVE-2023-50381Three os command injection vulnerabilities exist in the boa …7.2
- CVE-2023-50382Three os command injection vulnerabilities exist in the boa …7.2
- CVE-2023-50383Three os command injection vulnerabilities exist in the boa …7.2
- CVE-2023-50386Improper Control of Dynamically-Managed Code Resources, Unre…8.8
- CVE-2023-50395 SQL Injection Remote Code Execution Vulnerability was found…8
- CVE-2023-5041The Track The Click WordPress plugin before 0.3.12 does not …8.8
- CVE-2023-5042Sensitive information disclosure due to insecure folder perm…7.5
- CVE-2023-50422SAP BTP Security Services Integration Library ([Java] cloud-…9.8
- CVE-2023-50423SAP BTP Security Services Integration Library ([Python] sap-…9.8
- CVE-2023-50424SAP BTP Security Services Integration Library ([Golang] gith…9.8
Are you affected by CVE-2023-50387?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
