CVE-2022-3080
published 2022-09-21CVE-2022-3080: By sending specific queries to the resolver, an attacker can cause named to crash.
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.55%
72.4th percentile
By sending specific queries to the resolver, an attacker can cause named to crash.
Affected
23 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.7-1 (bookworm) | bind9 1:9.18.7-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | >= 9.16.14 < 9.16.33 | 9.16.33 |
| isc | bind | >= 9.18.0 < 9.18.7 | 9.18.7 |
| isc | bind | >= 9.19.0 < 9.19.5 | 9.19.5 |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | — | — |
| isc | bind9 | >= 0 < 1:9.16.33-1~deb11u1 | 1:9.16.33-1~deb11u1 |
| isc | bind9 | >= 0 < 1:9.18.7-1 | 1:9.18.7-1 |
| isc | bind9 | >= 0 < 1:9.18.7-1 | 1:9.18.7-1 |
| isc | bind9 | >= 0 < 1:9.18.7-1 | 1:9.18.7-1 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.18 | 1:9.11.3+dfsg-1ubuntu1.18 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.11 | 1:9.16.1-0ubuntu2.11 |
| isc | bind9 | >= 0 < 1:9.18.1-1ubuntu1.2 | 1:9.18.1-1ubuntu1.2 |
| msrc | cbl2_bind_9.16.33-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_bind_9.16.33-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly
vendor_redhat·2022-09-21·CVSS 7.5
CVE-2022-3080 [HIGH] CWE-20 bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly
bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly
By sending specific queries to the resolver, an attacker can cause named to crash.
A flaw was found in the Bind package, where the resolver can crash when stale cache and stale answers are enabled, option stale-answer-client-timeout is set to 0 and there is a stale CNAME in the cache for an incoming query. By sending specific queries to the resolver, an attacker can cause named to crash.
Statement: This issue affects versions 9.16.14 and higher of the Bind package. Therefore Red Hat Enterprise Linux 6 and 7 are not impacted.
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Package: bind (Red Hat Enterprise
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2022-09-21·CVSS 5.3
CVE-2022-3080 [MEDIUM] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Yehuda Afek, Anat Bremler-Barr, and Shani Stajnrod discovered that Bind
incorrectly handled large delegations. A remote attacker could possibly use
this issue to reduce performance, leading to a denial of service.
(CVE-2022-2795)
It was discovered that Bind incorrectly handled statistics requests. A
remote attacker could possibly use this issue to obtain sensitive memory
contents, or cause a denial of service. This issue only affected Ubuntu
22.04 LTS. (CVE-2022-2881)
It was discovered that Bind incorrectly handled memory when processing
certain Diffie-Hellman key exchanges. A remote attacker could use this
issue to consume resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LT
Microsoft
BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly
vendor_msrc·2022-09-13·CVSS 7.5
CVE-2022-3080 [HIGH] BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly
BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Debian
CVE-2022-3080: bind9 - By sending specific queries to the resolver, an attacker can cause named to cras...
vendor_debian·2022·CVSS 7.5
CVE-2022-3080 [HIGH] CVE-2022-3080: bind9 - By sending specific queries to the resolver, an attacker can cause named to cras...
By sending specific queries to the resolver, an attacker can cause named to crash.
Scope: local
bookworm: resolved (fixed in 1:9.18.7-1)
bullseye: resolved (fixed in 1:9.16.33-1~deb11u1)
forky: resolved (fixed in 1:9.18.7-1)
sid: resolved (fixed in 1:9.18.7-1)
trixie: resolved (fixed in 1:9.18.7-1)
GHSA
GHSA-7mrh-jrcg-wc76: By sending specific queries to the resolver, an attacker can cause named to crash
ghsa_unreviewed·2022-09-22
CVE-2022-3080 [HIGH] CWE-613 GHSA-7mrh-jrcg-wc76: By sending specific queries to the resolver, an attacker can cause named to crash
By sending specific queries to the resolver, an attacker can cause named to crash.
OSV
CVE-2022-3080: By sending specific queries to the resolver, an attacker can cause named to crash
osv·2022-09-21·CVSS 7.5
CVE-2022-3080 [HIGH] CVE-2022-3080: By sending specific queries to the resolver, an attacker can cause named to crash
By sending specific queries to the resolver, an attacker can cause named to crash.
OSV
bind9 vulnerabilities
osv·2022-09-21·CVSS 5.3
CVE-2022-2795 [MEDIUM] bind9 vulnerabilities
bind9 vulnerabilities
Yehuda Afek, Anat Bremler-Barr, and Shani Stajnrod discovered that Bind
incorrectly handled large delegations. A remote attacker could possibly use
this issue to reduce performance, leading to a denial of service.
(CVE-2022-2795)
It was discovered that Bind incorrectly handled statistics requests. A
remote attacker could possibly use this issue to obtain sensitive memory
contents, or cause a denial of service. This issue only affected Ubuntu
22.04 LTS. (CVE-2022-2881)
It was discovered that Bind incorrectly handled memory when processing
certain Diffie-Hellman key exchanges. A remote attacker could use this
issue to consume resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS. (CVE-2022-2906)
Maksym Odinintsev discovered that Bind i
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2022/09/21/3https://kb.isc.org/docs/cve-2022-3080https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/https://security.gentoo.org/glsa/202210-25https://security.netapp.com/advisory/ntap-20240621-0002/https://www.debian.org/security/2022/dsa-5235http://www.openwall.com/lists/oss-security/2022/09/21/3https://kb.isc.org/docs/cve-2022-3080https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/https://security.gentoo.org/glsa/202210-25https://security.netapp.com/advisory/ntap-20240621-0002/https://www.debian.org/security/2022/dsa-5235
2022-09-21
Published