CVE-2023-50387: Unbound: disclosure of CVE-2023-50387 and CVE-2023-50868 DNSSEC validation vulnerabilities
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Other sources
ISC BIND is vulnerable to a denial of service, caused by an error when processing responses coming from specially crafted DNSSEC-signed zones. By flooding the target server with queries, a remote attacker could exploit this vulnerability to cause CPU exhaustion on a DNSSEC-validating resolver.
— IBM
MITRE: CVE-2023-50387 DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers
— Microsoft
The processing of responses coming from specially crafted DNSSEC-signed zones can cause CPU exhaustion on a DNSSEC-validating resolver.
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50387?
CVE-2023-50387 has been assessed with a severity level that allows remote attackers to cause a denial of service.
What systems are affected by CVE-2023-50387?
CVE-2023-50387 affects multiple versions of Microsoft Windows Server, various DNS software including BIND and PowerDNS, and several Linux distributions.
How do I fix CVE-2023-50387?
To fix CVE-2023-50387, apply the specific patches and updates provided by your software vendor.
What is the nature of the vulnerability in CVE-2023-50387?
The vulnerability in CVE-2023-50387 originates from certain DNSSEC aspects of the DNS protocol that can be exploited for denial of service.
Are there any workarounds for CVE-2023-50387?
While updating is highly recommended, temporary network configurations to limit DNS response processing might serve as a workaround for CVE-2023-50387.