CVE-2022-38178
HIGHnamed - Memory Corruption
Title source: llmDescription
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
References (9)
Scores
CVSS v3
7.5
EPSS
0.0187
EPSS Percentile
82.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-401
Status
published
Affected Products (28)
isc/bind
< 9.9.13
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
isc/bind
... and 13 more
Timeline
Published
Sep 21, 2022
Tracked Since
Feb 18, 2026