CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 100.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-770
- Affected
- redhat/enterprise linux · microsoft/windows server 2008 · microsoft/windows server 2012 · microsoft/windows server 2016 · microsoft/windows server 2019 · microsoft/windows server 2022 · microsoft/windows server 2022 23h2 · fedoraproject/fedora · thekelleys/dnsmasq · nic/knot resolver · powerdns/recursor · isc/bind · nlnetlabs/unbound
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2024/02/16/2Mailing List
- http://www.openwall.com/lists/oss-security/2024/02/16/3Mailing List
- https://access.redhat.com/security/cve/CVE-2023-50387Third Party Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1219823Issue Tracking
- https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.htmlThird Party Advisory
- https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1Patch
- https://kb.isc.org/docs/cve-2023-50387Third Party Advisory, VDB Entry
- https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html
- https://lists.debian.org/debian-lts-announce/2024/05/msg00011.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6FV5O347JTX7P5OZA6NGO4MKTXRXMKOZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HVRDSJVZKMCXKKPP6PNR62T7RWZ3YSDZ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IGSLGKUAQTW5JPPZCMF5YPEYALLRUZZ6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGS7JN6FZXUSTC2XKQHH27574XOULYYJ/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TEXGOYGW7DBS3N2QSSQONZ4ENIRQEAPG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UQESRWMJCF4JEYJEAKLRM6CT55GLJAB7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDZFMEKQTZ4L7RY46FCENWFB5MDT263R/
- https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.htmlMailing List, Third Party Advisory
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-50387Patch, Vendor Advisory
- https://news.ycombinator.com/item?id=39367411Third Party Advisory
- https://news.ycombinator.com/item?id=39372384Issue Tracking
- https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/Vendor Advisory
- https://security.netapp.com/advisory/ntap-20240307-0007/
- https://www.athene-center.de/aktuelles/key-trapThird Party Advisory
- https://www.athene-center.de/fileadmin/content/PDF/Technical_Report_KeyTrap.pdfTechnical Description, Third Party Advisory
- https://www.isc.org/blogs/2024-bind-security-release/Third Party Advisory
- https://www.securityweek.com/keytrap-dns-attack-could-disable-large-parts-of-internet-researchers/Press/Media Coverage, Third Party Advisory
- https://www.theregister.com/2024/02/13/dnssec_vulnerability_internet/Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.