CVE-2023-26249Allocation of Resources Without Limits or Throttling in Knot Resolver

Severity
7.5HIGHNVD
EPSS
0.4%
top 39.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 21

Description

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDnic/knot_resolver< 5.6.0
Debiancz.nic/knot-resolver< 5.6.0-1+2

🔴Vulnerability Details

3
OSV
CVE-2023-26249: Knot Resolver before 52023-02-21
GHSA
GHSA-38wr-pjxc-vgf7: Knot Resolver before 52023-02-21
CVEList
CVE-2023-26249: Knot Resolver before 52023-02-21

📋Vendor Advisories

1
Debian
CVE-2023-26249: knot-resolver - Knot Resolver before 5.6.0 enables attackers to consume its resources, launching...2023
CVE-2023-26249 — NIC Knot Resolver vulnerability | cvebase