This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5329-1 | bind9 security update |
EUVD |
EUVD-2022-43092 | BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1. |
Ubuntu USN |
USN-5827-1 | Bind vulnerabilities |
Solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.37, 9.18.11, 9.19.9, or 9.16.37-S1.
Workaround
Setting `stale-answer-client-timeout` to `0` or to `off/disabled` will prevent BIND from crashing due to this issue.
Tue, 01 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: isc
Published:
Updated: 2025-04-01T14:10:47.439Z
Reserved: 2022-10-28T07:04:32.966Z
Link: CVE-2022-3736
Updated: 2024-08-03T01:20:57.535Z
Status : Modified
Published: 2023-01-26T21:15:57.940
Modified: 2025-04-01T15:15:53.150
Link: CVE-2022-3736
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN