CVE-2022-38177High· 7.5▾ TwilightBy spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 1.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.7%
2.7% → 3.2%
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
bind >= 9.8.4, <= 9.16.32bind = 9.9.3bind = 9.9.12bind = 9.9.13bind = 9.10.5bind = 9.10.7bind = 9.11.3bind = 9.11.5bind = 9.11.6bind = 9.11.7bind = 9.11.8bind = 9.11.12bind = 9.11.14-s1bind = 9.11.19-s1bind = 9.11.21bind = 9.11.27bind = 9.11.29bind = 9.11.35bind = 9.11.37bind = 9.16.8bind = 9.16.11bind = 9.16.13bind = 9.16.21bind = 9.16.32debian_linux = 10.0debian_linux = 11.0fedora = 35fedora = 36fedora = 37active_iq_unified_managerRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-38178High· 7.5By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak
CVE-2022-2795Medium· 5.3By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
CVE-2026-3104High· 7.5A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 …
CVE-2026-81563High· 7.5A BIND resolver encountering an SVCB/HTTPS AliasMode record referencing 14 or more SVCB/HTTPS ServiceMode records may fail to properly deallocate internal resources
CVE-2020-8619Medium· 4.9In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at le…
CVE-2018-5745Medium· 4.9"managed-keys" is a feature which allows a BIND resolver to automatically maintain the keys used by trust anchors which operators configure for use in DNSSEC validation