cbcvebase.
CVE-2023-50868
published 2024-02-14

CVE-2023-50868: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU…

PriorityP356high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
81.73%
99.6th percentile
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
cz.nicknot-resolver>= 0 < 5.6.0-1+deb12u15.6.0-1+deb12u1
cz.nicknot-resolver>= 0 < 5.7.1-15.7.1-1
cz.nicknot-resolver>= 0 < 5.7.1-15.7.1-1
debianbind9< bind9 1:9.18.24-1 (bookworm)bind9 1:9.18.24-1 (bookworm)
debiandebian_linux
debiandebian_linux
debiandnsjava< bind9 1:9.18.24-1 (bookworm)bind9 1:9.18.24-1 (bookworm)
debiandnsmasq< bind9 1:9.18.24-1 (bookworm)bind9 1:9.18.24-1 (bookworm)
debianknot-resolver< bind9 1:9.18.24-1 (bookworm)bind9 1:9.18.24-1 (bookworm)
debianpdns-recursor< bind9 1:9.18.24-1 (bookworm)bind9 1:9.18.24-1 (bookworm)
debiansystemd< bind9 1:9.18.24-1 (bookworm)bind9 1:9.18.24-1 (bookworm)
debianunbound< bind9 1:9.18.24-1 (bookworm)bind9 1:9.18.24-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
iscbind>= 9.0.0 < 9.16.489.16.48
iscbind>= 9.18.0 < 9.18.249.18.24
iscbind>= 9.18.11 < 9.18.249.18.24
iscbind>= 9.19.0 < 9.19.219.19.21
iscbind>= 9.9.3 < 9.16.489.16.48
iscbind9>= 0 < 1:9.16.48-11:9.16.48-1
iscbind9>= 0 < 1:9.18.24-11:9.18.24-1
iscbind9>= 0 < 1:9.19.21-11:9.19.21-1
iscbind9>= 0 < 1:9.19.21-11:9.19.21-1
iscbind9>= 0 < 1:9.16.48-0ubuntu0.20.04.11:9.16.48-0ubuntu0.20.04.1
iscbind9>= 0 < 1:9.18.18-0ubuntu0.22.04.21:9.18.18-0ubuntu0.22.04.2

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://github.com/Goethe-Universitat-Cybersecurity/NSEC3-Encloser-Attack
  • Monitor DNS resolvers for anomalous CPU spikes triggered by high volumes of DNSSEC NSEC3 responses; the attack can create a 72x increase in CPU instruction count even when resolvers follow RFC5155 iteration limits.
  • Alert on packet loss rates of 2.7%–30% on benign DNS traffic when a resolver is receiving approximately 150 or more malicious NSEC3 records per second, which is a threshold indicative of an active NSEC3-encloser attack.
  • Inspect NSEC3 records in DNSSEC responses for use of salt combined with high hash iteration counts; the presence of salt increases resolver CPU load by ~30% and is a key attack amplifier.
  • Flag DNSSEC-signed zones using high hash iteration counts in NSEC3 records as potential abuse vectors; 77% of NSEC3 domains observed in the wild use a high number of hash iterations.
  • The attack vector is a random subdomain (NXDOMAIN) flood targeting DNSSEC-validating resolvers; queries for non-existent subdomains force the resolver to process crafted NSEC3 closest-encloser proof records with expensive SHA-1 hash iterations.
  • ·The attack is effective even when resolvers comply with RFC5155 iteration count recommendations; simply enforcing RFC5155 limits is insufficient to fully mitigate CPU exhaustion.
  • ·The attack requires a relatively high query rate to cause significant packet loss, and the impact on traffic loss is relatively low compared to other DNS attacks.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.