CVE-2022-3488: high-severity vulnerability in ISC BIND 9
named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
BIND DNS server crashes when it receives certain malformed responses with ECS options during repeated DNS queries. This causes the DNS service to stop working, affecting all users relying on that server.
An attacker can trigger an assertion failure in BIND's ECS (EDNS Client Subnet) option processing by sending crafted responses to iterative queries where the first response contains invalid ECS data (e.g., mismatched query/answer names) followed by a second valid response. The vulnerability affects BIND 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1, resulting in DoS via process termination.
In the same product, most dangerous first.