CVE-2022-2906

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
References
Link Resource
https://kb.isc.org/docs/cve-2022-2906 Patch Vendor Advisory
http://www.openwall.com/lists/oss-security/2022/09/21/3 Mailing List Patch Third Party Advisory
https://security.gentoo.org/glsa/202210-25 Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*

Information

Published : 2022-09-21 04:15

Updated : 2022-12-02 17:06


NVD link : CVE-2022-2906

Mitre link : CVE-2022-2906


JSON object : View

CWE
CWE-401

Missing Release of Memory after Effective Lifetime

Advertisement

dedicated server usa

Products Affected

isc

  • bind