CVE-2022-2795Medium· 5.3▾ SunlitBy flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.8%
1.8% → 2.2%
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
bind >= 9.0.0, < 9.16.33bind >= 9.18.0, < 9.18.7bind >= 9.19.0, < 9.19.5bind = 9.9.3bind = 9.9.12bind = 9.9.13bind = 9.10.5bind = 9.10.7bind = 9.11.3bind = 9.11.5bind = 9.11.6bind = 9.11.7bind = 9.11.8bind = 9.11.12bind = 9.11.14-s1bind = 9.11.19-s1bind = 9.11.21bind = 9.11.27bind = 9.11.29bind = 9.11.35bind = 9.11.37bind = 9.16.8bind = 9.16.11bind = 9.16.13bind = 9.16.21bind = 9.16.32debian_linux = 10.0debian_linux = 11.0fedora = 35fedora = 36fedora = 37Upgrade past the affected range:
bind 9.19.5Connected by shared product, vendor, weakness, or advisory.
CVE-2022-38178High· 7.5By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak
CVE-2022-38177High· 7.5By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak
CVE-2020-8619Medium· 4.9In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at le…
CVE-2018-5745Medium· 4.9"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation
CVE-2026-3104High· 7.5A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 …
CVE-2026-3039High· 7.5BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets