CVE-2023-50387
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
A flaw in DNSSEC (the security system for DNS) allows attackers to overwhelm servers by sending specially crafted DNS responses that force excessive CPU usage. This happens when servers try to verify signatures on zones with many security keys.
CVE-2023-50387 exploits algorithmic complexity in DNSSEC validation by forcing servers to evaluate all combinations of DNSKEY and RRSIG records in zones with numerous entries. Remote attackers can trigger denial of service through malicious DNSSEC responses without authentication; the attack consumes significant CPU resources during cryptographic verification, affecting DNS resolver availability.