CVE-2023-50387: Fedoraproject Fedora
High severity, CVSS 7.5. EPSS: 100% chance of exploitation in the next 30 days.
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Affected products
- Fedoraproject Fedora: version 39 only
- ISC BIND: from 9.0.0, up to and including 9.16.46; from 9.18.0, up to and including 9.18.22; from 9.19.0, up to and including 9.19.20
- Microsoft Windows Server 2008: version r2 only
- Microsoft Windows Server 2012: affected versions not specified; version r2 only
- Microsoft Windows Server 2016: affected versions not specified
- Microsoft Windows Server 2019: affected versions not specified
- Microsoft Windows Server 2022: affected versions not specified
- Microsoft Windows Server 2022 23h2: affected versions not specified
- Nic Knot Resolver: before 5.71 (fixed in 5.71)
- Nlnetlabs Unbound: before 1.19.1 (fixed in 1.19.1)
- Powerdns Recursor: from 4.8.0, before 4.8.6 (fixed in 4.8.6); from 4.9.0, before 4.9.3 (fixed in 4.9.3); from 5.0.0, before 5.0.2 (fixed in 5.0.2)
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 9.0 only
- Thekelleys Dnsmasq: before 2.90 (fixed in 2.90)
Published 2024-02-14. Last modified 2026-06-17.