CVE-2022-2881
published 2022-09-21CVE-2022-2881: The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
PriorityP336high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
1.12%
62.9th percentile
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.7-1 (bookworm) | bind9 1:9.18.7-1 (bookworm) |
| isc | bind | >= 9.18.0 < 9.18.7 | 9.18.7 |
| isc | bind | >= 9.19.0 < 9.19.5 | 9.19.5 |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | >= 0 < 1:9.18.7-1 | 1:9.18.7-1 |
| isc | bind9 | >= 0 < 1:9.18.7-1 | 1:9.18.7-1 |
| isc | bind9 | >= 0 < 1:9.18.7-1 | 1:9.18.7-1 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.18 | 1:9.11.3+dfsg-1ubuntu1.18 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.11 | 1:9.16.1-0ubuntu2.11 |
| isc | bind9 | >= 0 < 1:9.18.1-1ubuntu1.2 | 1:9.18.1-1ubuntu1.2 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
osv8.2HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: buffer overread in statistics channel code
vendor_redhat·2022-09-21·CVSS 5.5
CVE-2022-2881 [MEDIUM] CWE-126 bind: buffer overread in statistics channel code
bind: buffer overread in statistics channel code
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
A flaw was found in the Bind package. When an HTTP connection was reused to request statistics from the stats channel, the content length of successive responses could grow in size past the end of the allocated buffer, affecting the availability.
Statement: This flaw only affects versions BIND-9.18.0 and higher, whereas Red Hat ships BIND-9.16 and lower versions. Therefore, versions of BIND shipped with Red Hat Products are not affected by this flaw.
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Package: bind (Red Hat Enterprise Linux 8) - Not a
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2022-09-21·CVSS 5.3
CVE-2022-3080 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Yehuda Afek, Anat Bremler-Barr, and Shani Stajnrod discovered that Bind
incorrectly handled large delegations. A remote attacker could possibly use
this issue to reduce performance, leading to a denial of service.
(CVE-2022-2795)
It was discovered that Bind incorrectly handled statistics requests. A
remote attacker could possibly use this issue to obtain sensitive memory
contents, or cause a denial of service. This issue only affected Ubuntu
22.04 LTS. (CVE-2022-2881)
It was discovered that Bind incorrectly handled memory when processing
certain Diffie-Hellman key exchanges. A remote attacker could use this
issue to consume resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LT
Debian
CVE-2022-2881: bind9 - The underlying bug might cause read past end of the buffer and either read memor...
vendor_debian·2022·CVSS 5.5
CVE-2022-2881 [MEDIUM] CVE-2022-2881: bind9 - The underlying bug might cause read past end of the buffer and either read memor...
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
Scope: local
bookworm: resolved (fixed in 1:9.18.7-1)
bullseye: open
forky: resolved (fixed in 1:9.18.7-1)
sid: resolved (fixed in 1:9.18.7-1)
trixie: resolved (fixed in 1:9.18.7-1)
GHSA
GHSA-gjh8-h6gp-pqgr: The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process
ghsa_unreviewed·2022-09-22
CVE-2022-2881 [HIGH] CWE-125 GHSA-gjh8-h6gp-pqgr: The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
OSV
bind9 vulnerabilities
osv·2022-09-21·CVSS 5.3
CVE-2022-2795 [MEDIUM] bind9 vulnerabilities
bind9 vulnerabilities
Yehuda Afek, Anat Bremler-Barr, and Shani Stajnrod discovered that Bind
incorrectly handled large delegations. A remote attacker could possibly use
this issue to reduce performance, leading to a denial of service.
(CVE-2022-2795)
It was discovered that Bind incorrectly handled statistics requests. A
remote attacker could possibly use this issue to obtain sensitive memory
contents, or cause a denial of service. This issue only affected Ubuntu
22.04 LTS. (CVE-2022-2881)
It was discovered that Bind incorrectly handled memory when processing
certain Diffie-Hellman key exchanges. A remote attacker could use this
issue to consume resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS. (CVE-2022-2906)
Maksym Odinintsev discovered that Bind i
OSV
CVE-2022-2881: The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process
osv·2022-09-21·CVSS 8.2
CVE-2022-2881 [HIGH] CVE-2022-2881: The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
No detection rules found.
No public exploits indexed.
2022-09-21
Published