CVE-2022-40188: High severity nic Knot Resolver vulnerability
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/knot-resolverto a version that resolves this vulnerability.Fixed in 3.2.1-3+deb10u1Fixed in 5.6.0-1Fixed in 5.7.0-1 - Upgrade
Upgrade
ubuntu/knot-resolverto a version that resolves this vulnerability.Fixed in 5.5.1-5ubuntu0.22.10.1 - Upgrade
Upgrade
ubuntu/knot-resolverto a version that resolves this vulnerability.Fixed in 5.5.3-1 - Upgrade
Upgrade
ubuntu/knot-resolverto a version that resolves this vulnerability.Fixed in 2.1.1-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/knot-resolverto a version that resolves this vulnerability.Fixed in 3.2.1-3ubuntu2.1 - Upgrade
Upgrade
ubuntu/knot-resolverto a version that resolves this vulnerability.Fixed in 5.4.4-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/knot-resolverto a version that resolves this vulnerability.Fixed in 1.0.0~ - Upgrade
Upgrade
Knot Resolverto a version that resolves this vulnerability.Fixed in 5.5.3
Event History
Frequently Asked Questions
What is CVE-2022-40188?
CVE-2022-40188 is a vulnerability in Knot Resolver before version 5.5.3 that allows remote attackers to cause a denial of service (CPU consumption) due to algorithmic complexity.
How severe is CVE-2022-40188?
CVE-2022-40188 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2022-40188?
Knot Resolver versions up to and including 5.5.1-5ubuntu0.22.10.1, 5.5.3-1, 2.1.1-1ubuntu0.1~, 3.2.1-3ubuntu2.1, 5.4.4-1ubuntu0.1~, and 1.0.0~ are affected.
How do I fix CVE-2022-40188?
To fix CVE-2022-40188, update Knot Resolver to version 5.5.3 or higher.
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-40188?
The Common Weakness Enumeration (CWE) ID for CVE-2022-40188 is CWE-407.