CVE-2022-0667
published 2022-03-22CVE-2022-0667: When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.33%
68.0th percentile
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.1-1 (bookworm) | bind9 1:9.18.1-1 (bookworm) |
| isc | bind | — | — |
| isc | bind9 | >= 0 < 1:9.18.1-1 | 1:9.18.1-1 |
| isc | bind9 | >= 0 < 1:9.18.1-1 | 1:9.18.1-1 |
| isc | bind9 | >= 0 < 1:9.18.1-1 | 1:9.18.1-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: When chasing DS records, a timed-out or artificially delayed fetch could cause 'named' to crash while resuming a DS lookup
vendor_redhat·2022-03-16·CVSS 7.5
CVE-2022-0667 [HIGH] CWE-617 bind: When chasing DS records, a timed-out or artificially delayed fetch could cause 'named' to crash while resuming a DS lookup
bind: When chasing DS records, a timed-out or artificially delayed fetch could cause 'named' to crash while resuming a DS lookup
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
An assertion check flaw was found in BIND, with a refactoration of recursive client code that introduced a "backstop lifetime timer." While BIND processes a request for a DS record that needs to be forwarded, it waits until this processing is complete or until the backstop lifetime timer has timed out. As a result of this timeout, the resume_dslookup() function is called, which does not test whether the fetch has shut down previously. This issue triggers an assertion failure, which could cause the BIND process to terminate.
Statement: This flaw only affects BIND-9.18.0, whereas Red Hat
Debian
CVE-2022-0667: bind9 - When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
vendor_debian·2022·CVSS 7.5
CVE-2022-0667 [HIGH] CVE-2022-0667: bind9 - When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
Scope: local
bookworm: resolved (fixed in 1:9.18.1-1)
bullseye: resolved
forky: resolved (fixed in 1:9.18.1-1)
sid: resolved (fixed in 1:9.18.1-1)
trixie: resolved (fixed in 1:9.18.1-1)
GHSA
GHSA-mmmq-7jwv-j64j: When the vulnerability is triggered the BIND process will exit
ghsa_unreviewed·2022-03-23
CVE-2022-0667 [HIGH] CWE-617 GHSA-mmmq-7jwv-j64j: When the vulnerability is triggered the BIND process will exit
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
OSV
CVE-2022-0667: When the vulnerability is triggered the BIND process will exit
osv·2022-03-22·CVSS 7.5
CVE-2022-0667 [HIGH] CVE-2022-0667: When the vulnerability is triggered the BIND process will exit
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
No detection rules found.
No public exploits indexed.
2022-03-22
Published