CVE-2023-50868: Unbound: disclosure of CVE-2023-50387 and CVE-2023-50868 DNSSEC validation vulnerabilities
ISC BIND is vulnerable to a denial of service, caused by an error when preparing an NSEC3 closest encloser proof. By flooding the target resolver with queries, a remote attacker could exploit this vulnerability to cause CPU exhaustion on a DNSSEC-validating resolver.
Other sources
MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU
— Microsoft
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
— Launchpad
The processing of responses coming from DNSSEC-signed zones using NSEC3 can cause CPU exhaustion on a DNSSEC-validating resolver.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50868?
CVE-2023-50868 is classified as a high severity vulnerability due to its potential for denial of service attacks.
How does CVE-2023-50868 affect DNSSEC-validating resolvers?
CVE-2023-50868 can cause CPU exhaustion on DNSSEC-validating resolvers when exploited by an attacker flooding the resolver with queries.
What are the affected products in CVE-2023-50868?
CVE-2023-50868 affects multiple versions of Microsoft Windows Server, F5 BIG-IP, and several Debian packages such as bind9.
How can I mitigate the impact of CVE-2023-50868?
To mitigate CVE-2023-50868, apply the latest patches provided by the affected software vendors to remediate the vulnerability.
What type of attack is possible due to CVE-2023-50868?
CVE-2023-50868 allows for a denial of service attack, leading to performance issues for affected DNS resolvers.