CVE-2022-2795
Publication date 21 September 2022
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
Status
Package | Ubuntu Release | Status |
---|---|---|
bind9 | 24.10 oracular |
Fixed 1:9.18.4-2ubuntu2
|
24.04 LTS noble |
Fixed 1:9.18.4-2ubuntu2
|
|
22.04 LTS jammy |
Fixed 1:9.18.1-1ubuntu1.2
|
|
20.04 LTS focal |
Fixed 1:9.16.1-0ubuntu2.11
|
|
18.04 LTS bionic |
Fixed 1:9.11.3 dfsg-1ubuntu1.18
|
|
16.04 LTS xenial |
Fixed 1:9.10.3.dfsg.P4-8ubuntu1.19 esm3
|
|
14.04 LTS trusty |
Fixed 1:9.9.5.dfsg-3ubuntu0.19 esm7
|
|
bind9-libs | 24.10 oracular | Not in release |
24.04 LTS noble | Not in release | |
22.04 LTS jammy |
Needs evaluation
|
|
20.04 LTS focal |
Needs evaluation
|
|
18.04 LTS bionic | Not in release | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
isc-dhcp | 24.10 oracular |
Vulnerable
|
24.04 LTS noble |
Vulnerable
|
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProNotes
alexmurray
As of isc-dhcp-4.4.3-1, isc-dhcp vendors bind9 libs
mdeslaur
This is unlikely to affect isc-dhcp's use of bind9-libs and the vendored bind9 libs, marking as negligible
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.3 · Medium |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | Low |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
References
Related Ubuntu Security Notices (USN)
- USN-5626-1
- Bind vulnerabilities
- 21 September 2022
- USN-5626-2
- Bind vulnerabilities
- 21 September 2022