ZeroHour

CVE-2023-50387

CVSS 3.1
7.5 high
EPSS
100%p100
Published
()
Modified
Description

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

Vendors
redhatmicrosoftfedoraprojectthekelleysnicpowerdnsiscnlnetlabs
Products
enterprise linux, windows server 2008, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2, fedora, dnsmasq, knot resolver, recursor, bind
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news