CVE-2023-50868: Debian Linux
High severity, CVSS 7.5. EPSS: 73.7% chance of exploitation in the next 30 days.
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Affected products
- Debian Debian Linux: version 10.0 only; version 11.0 only
- Fedoraproject Fedora: version 38 only; version 39 only
- ISC BIND: from 9.0.0, before 9.16.48 (fixed in 9.16.48); from 9.9.3, before 9.16.48 (fixed in 9.16.48); from 9.18.0, before 9.18.24 (fixed in 9.18.24); from 9.18.11, before 9.18.24 (fixed in 9.18.24); from 9.19.0, before 9.19.21 (fixed in 9.19.21)
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Bootstrap OS: affected versions not specified
- Netapp Hci Baseboard Management Controller: affected versions not specified
- Powerdns Recursor: before 4.8.5 (fixed in 4.8.5); from 4.9.0, before 4.9.3 (fixed in 4.9.3); from 5.0.0, before 5.0.2 (fixed in 5.0.2)
- Red Hat Enterprise Linux: version 6.0 only; version 7.0 only; version 8.0 only; version 8.2 only; version 8.4 only
Published 2024-02-14. Last modified 2026-06-17.