← back
CVE-2023-50387highCWE-770

CVE-2023-50387

43Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 100%
exploitation probability
100%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
37 products (4,008 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux AppStream EUS (v.8.6) · Red Hat Enterprise Linux AppStream EUS (v.8.8) · Red Hat Enterprise Linux AppStream (v. 9) · and others 32
Not affected
4 products (115 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux BaseOS (v. 8) · Red Hat Enterprise Linux 10 · Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux 7
In short

A flaw in DNSSEC (the security system for DNS) allows attackers to overwhelm servers by sending specially crafted DNS responses that force excessive CPU usage. This happens when servers try to verify signatures on zones with many security keys.

Technical detail

CVE-2023-50387 exploits algorithmic complexity in DNSSEC validation by forcing servers to evaluate all combinations of DNSKEY and RRSIG records in zones with numerous entries. Remote attackers can trigger denial of service through malicious DNSSEC responses without authentication; the attack consumes significant CPU resources during cryptographic verification, affecting DNS resolver availability.

Summary generated and translated by AI from the official description.
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · n/a