CVE-2022-3736
published 2023-01-26CVE-2022-3736: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver…
PriorityP358high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
48.43%
98.7th percentile
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query.
This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.11-1 (bookworm) | bind9 1:9.18.11-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | >= 0 < 9.16.37-r0 | 9.16.37-r0 |
| isc | bind | >= 0 < 9.16.37-r0 | 9.16.37-r0 |
| isc | bind | >= 0 < 9.16.37-r0 | 9.16.37-r0 |
| isc | bind | >= 0 < 9.18.11-r0 | 9.18.11-r0 |
| isc | bind | >= 0 < 9.18.11-r0 | 9.18.11-r0 |
| isc | bind | >= 0 < 9.18.11-r0 | 9.18.11-r0 |
| isc | bind | >= 0 < 9.18.11-r0 | 9.18.11-r0 |
| isc | bind | >= 0 < 9.18.11-r0 | 9.18.11-r0 |
| isc | bind | >= 0 < 9.18.11-r0 | 9.18.11-r0 |
| isc | bind | >= 0 < 9.18.11-r0 | 9.18.11-r0 |
| isc | bind | >= 9.16.12 < 9.16.37 | 9.16.37 |
| isc | bind | >= 9.18.0 < 9.18.11 | 9.18.11 |
| isc | bind | >= 9.19.0 < 9.19.9 | 9.19.9 |
| isc | bind9 | >= 0 < 1:9.16.37-1~deb11u1 | 1:9.16.37-1~deb11u1 |
| isc | bind9 | >= 0 < 1:9.18.11-1 | 1:9.18.11-1 |
| isc | bind9 | >= 0 < 1:9.18.11-1 | 1:9.18.11-1 |
| isc | bind9 | >= 0 < 1:9.18.11-1 | 1:9.18.11-1 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.12 | 1:9.16.1-0ubuntu2.12 |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: BIND 9 resolver crashes when stale cache and stale answers are enabled, stale-answer-client-timeout is set to a positive integer, AND the resolver receives an RRSIG query — monitor for named process crashes under these conditions ↗
- →Detect exploitation attempts by monitoring for RRSIG query types directed at BIND resolvers with stale-answer-client-timeout configured to a positive integer ↗
- →The vulnerable code path was introduced in BIND 9.16.12 via the stale-answer-client-timeout option; flag any named instances running versions 9.16.12–9.16.36, 9.18.0–9.18.10, 9.19.0–9.19.8, or 9.16.12-S1–9.16.36-S1 with this option enabled ↗
- →The flaw is specifically in the stale-answer-client-timeout implementation; audit named.conf for this option set to any positive integer as a risk indicator ↗
- ·Setting stale-answer-client-timeout to 0 or off/disabled fully mitigates the crash; only resolvers with a positive integer value for this option are vulnerable ↗
- ·Both stale cache AND stale answers must be enabled simultaneously alongside a positive stale-answer-client-timeout for the vulnerability to be triggerable — all three conditions are required ↗
- ·Red Hat Enterprise Linux 6, 7, and 8 ship BIND versions not affected by this CVE; only RHEL 9 and equivalent (e.g., Ubuntu 22.04 LTS, 22.10) carry vulnerable versions ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-3736: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the r
osv·2023-01-26·CVSS 7.5
CVE-2022-3736 [HIGH] CVE-2022-3736: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the r
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
GHSA
GHSA-5v6f-5gpq-2628: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the r
ghsa_unreviewed·2023-01-26
CVE-2022-3736 [HIGH] CWE-20 GHSA-5v6f-5gpq-2628: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the r
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
OSV
CVE-2022-3736: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the r
osv·2023-01-26·CVSS 7.5
CVE-2022-3736 [HIGH] CVE-2022-3736: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the r
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query.
This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
OSV
bind9 vulnerabilities
osv·2023-01-25·CVSS 7.5
CVE-2022-3094 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Rob Schulhof discovered that Bind incorrectly handled a large number of
UPDATE messages. A remote attacker could possibly use this issue to cause
Bind to consume resources, resulting in a denial of service.
(CVE-2022-3094)
Borja Marcos discovered that Bind incorrectly handled certain RRSIG
queries. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 22.10. (CVE-2022-3736)
Maksym Odinintsev discovered that Bind incorrectly handled certain answers
from stale cache. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. This issue only affected
Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-3924)
Red Hat
bind: sending specific queries to the resolver may cause a DoS
vendor_redhat·2023-01-25·CVSS 7.5
CVE-2022-3736 [HIGH] CWE-20 bind: sending specific queries to the resolver may cause a DoS
bind: sending specific queries to the resolver may cause a DoS
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query.
This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
A flaw was found in Bind, where a resolver crash is possible. When stale cache and stale answers are enabled, the option stale-answer-client-timeout is set to a positive integer, and the resolver receives an RRSIG query.
Statement: The flaw exists in the implementation of the stale-answer-client-timeout option, which was first effectively introduced in bind 9.16.12.
Mitigation: Setting stale-answer-client
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2023-01-25·CVSS 7.5
CVE-2022-3094 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Rob Schulhof discovered that Bind incorrectly handled a large number of
UPDATE messages. A remote attacker could possibly use this issue to cause
Bind to consume resources, resulting in a denial of service.
(CVE-2022-3094)
Borja Marcos discovered that Bind incorrectly handled certain RRSIG
queries. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
22.04 LTS and Ubuntu 22.10. (CVE-2022-3736)
Maksym Odinintsev discovered that Bind incorrectly handled certain answers
from stale cache. A remote attacker could possibly use this issue to cause
Bind to crash, resulting in a denial of service. This issue only affected
Ubuntu 22
Microsoft
named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
vendor_msrc·2023-01-10·CVSS 7.5
CVE-2022-3736 [HIGH] named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Remediation: CBL-
Debian
CVE-2022-3736: bind9 - BIND 9 resolver can crash when stale cache and stale answers are enabled, option...
vendor_debian·2022·CVSS 7.5
CVE-2022-3736 [HIGH] CVE-2022-3736: bind9 - BIND 9 resolver can crash when stale cache and stale answers are enabled, option...
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
Scope: local
bookworm: resolved (fixed in 1:9.18.11-1)
bullseye: resolved (fixed in 1:9.16.37-1~deb11u1)
forky: resolved (fixed in 1:9.18.11-1)
sid: resolved (fixed in 1:9.18.11-1)
trixie: resolved (fixed in 1:9.18.11-1)
No detection rules found.
No public exploits indexed.
Checkpoint
30th January – Threat Intelligence Report
blogs_checkpoint·2023-01-30
CVE-2022-3094 30th January – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th January – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th January, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHE
The ALPHV/BlackCat Ransomware group has allegedly hacked Westmont Hospitality Group, one of the largest privately-held hospitality businesses in the world. They claim to have obtained access to 262GB of the company’s data.
Check Point Harmony Endpoint and Threat Emulation provide protection against this threat (Ransomware.W
arXiv
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
arxiv_fulltext·2023-10-04
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
https://faculty.sites.uci.edu/zhouli/research/ Qifan Zhang ,
https://faculty.sites.uci.edu/zhouli/research/ Xuesong Bai ,
https://netsec.ccert.edu.cn/people/lx19 Xiang Li ,
https://netsec.ccert.edu.cn/people/duanhx/ Haixin Duan ,
https://netsec.ccert.edu.cn/people/qli/ Qi Li , and
https://faculty.sites.uci.edu/zhouli/ Zhou Li
Corresponding authors. Most of Xiang Li's work was done when visiting UCI as a project specialist.
https://uci.edu/University of California, Irvine,
https://www.tsinghua.edu.cn/en/Tsinghua University
Zhongguancun Laboratory,
https://www.qcl.edu.cn/Quan Cheng Laboratory
## Abstract
Domain Name System (DNS) is a critical component of the Internet. DNS resolvers, which act as the cache
2023-01-26
Published