CVE-2022-2906

HIGH

ISC Bind < 9.18.7 - Memory Leak

Title source: rule

Description

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

Scores

CVSS v3 7.5
EPSS 0.0086
EPSS Percentile 74.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-401
Status published

Affected Products (1)

isc/bind < 9.18.7

Timeline

Published Sep 21, 2022
Tracked Since Feb 18, 2026