CVE-2023-50387
Public on 2024-02-14
Modified on 2025-03-31
Description
Certain DNSSEC aspects of the DNS protocol (in RFC 4035 and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses when there is a zone with many DNSKEY and RRSIG records, aka the "KeyTrap" issue. The protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Severity
CVSS v3 Base Score
See breakdown
Affected Packages
Platform | Package | Release Date | Advisory | Status |
---|---|---|---|---|
HAQM Linux 1 | bind | No Fix Planned | ||
HAQM Linux 2 - Core | bind | 2024-04-24 | ALAS2-2024-2530 | Fixed |
HAQM Linux 2023 | bind | 2024-02-29 | ALAS2023-2024-550 | Fixed |
HAQM Linux 1 | dnsmasq | Not Affected | ||
HAQM Linux 2 - Core | dnsmasq | Not Affected | ||
HAQM Linux 2 - Dnsmasq2.85 Extra | dnsmasq | No Fix Planned | ||
HAQM Linux 2 - Dnsmasq Extra | dnsmasq | 2024-04-10 | ALAS2DNSMASQ-2024-002 | Fixed |
HAQM Linux 2023 | dnsmasq | 2024-02-29 | ALAS2023-2024-552 | Fixed |
HAQM Linux 1 | unbound | No Fix Planned | ||
HAQM Linux 2 - Unbound1.13 Extra | unbound | No Fix Planned | ||
HAQM Linux 2 - Core | unbound | 2024-02-29 | ALAS2-2024-2481 | Fixed |
HAQM Linux 2 - Unbound1.17 Extra | unbound | 2025-03-13 | ALAS2UNBOUND-1.17-2025-004 | Fixed |
HAQM Linux 2023 | unbound | 2024-02-29 | ALAS2023-2024-553 | Fixed |
CVSS Scores
Score Type | Score | Vector | |
---|---|---|---|
HAQM Linux | CVSSv3 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
NVD | CVSSv3 | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |