{"id":"SUSE-SU-2022:3682-1","summary":"Security update for bind","details":"This update for bind fixes the following issues:\n\n- CVE-2022-2795: Fixed potential performance degredation due to missing database lookup limits when processing large delegations (bsc#1203614).\n- CVE-2022-38177: Fixed a memory leak that could be externally triggered in the DNSSEC verification code for the ECDSA algorithm (bsc#1203619).\n- CVE-2022-38178: Fixed memory leaks that could be externally triggered in the DNSSEC verification code for the EdDSA algorithm (bsc#1203620).\n\nBugfixes:\n- Changed ownership of /var/lib/named/master from named:named to root:root (bsc#1201247)\n","modified":"2026-03-11T07:21:16.080235Z","published":"2022-10-21T09:42:59Z","related":["CVE-2022-2795","CVE-2022-38177","CVE-2022-38178"],"upstream":["CVE-2022-2795","CVE-2022-38177","CVE-2022-38178"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223682-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201247"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203614"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203619"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203620"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2795"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38177"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-38178"}],"affected":[{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP3","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.16.6-150300.22.21.2"}]}],"ecosystem_specific":{"binaries":[{"libdns1605":"9.16.6-150300.22.21.2","libirs-devel":"9.16.6-150300.22.21.2","libisc1606":"9.16.6-150300.22.21.2","libisccfg1600":"9.16.6-150300.22.21.2","bind-devel":"9.16.6-150300.22.21.2","bind-utils":"9.16.6-150300.22.21.2","libbind9-1600":"9.16.6-150300.22.21.2","libirs1601":"9.16.6-150300.22.21.2","libisccc1600":"9.16.6-150300.22.21.2","libns1604":"9.16.6-150300.22.21.2","python3-bind":"9.16.6-150300.22.21.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3682-1.json"}},{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Module for Basesystem 15 SP4","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.16.6-150300.22.21.2"}]}],"ecosystem_specific":{"binaries":[{"libisccfg1600":"9.16.6-150300.22.21.2","libns1604":"9.16.6-150300.22.21.2","libbind9-1600":"9.16.6-150300.22.21.2","libdns1605":"9.16.6-150300.22.21.2","libirs1601":"9.16.6-150300.22.21.2","libisc1606":"9.16.6-150300.22.21.2","libisccc1600":"9.16.6-150300.22.21.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3682-1.json"}},{"package":{"name":"bind","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP3","purl":"pkg:rpm/suse/bind&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.16.6-150300.22.21.2"}]}],"ecosystem_specific":{"binaries":[{"bind-doc":"9.16.6-150300.22.21.2","bind":"9.16.6-150300.22.21.2","bind-chrootenv":"9.16.6-150300.22.21.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3682-1.json"}},{"package":{"name":"bind","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/bind&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.16.6-150300.22.21.2"}]}],"ecosystem_specific":{"binaries":[{"python3-bind":"9.16.6-150300.22.21.2","bind-chrootenv":"9.16.6-150300.22.21.2","bind-utils":"9.16.6-150300.22.21.2","bind":"9.16.6-150300.22.21.2","libdns1605":"9.16.6-150300.22.21.2","libirs-devel":"9.16.6-150300.22.21.2","libisc1606":"9.16.6-150300.22.21.2","libisccc1600":"9.16.6-150300.22.21.2","libisccfg1600":"9.16.6-150300.22.21.2","bind-devel":"9.16.6-150300.22.21.2","bind-doc":"9.16.6-150300.22.21.2","libbind9-1600":"9.16.6-150300.22.21.2","libirs1601":"9.16.6-150300.22.21.2","libns1604":"9.16.6-150300.22.21.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3682-1.json"}},{"package":{"name":"bind","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/bind&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.16.6-150300.22.21.2"}]}],"ecosystem_specific":{"binaries":[{"bind-chrootenv":"9.16.6-150300.22.21.2","bind-devel":"9.16.6-150300.22.21.2","libdns1605":"9.16.6-150300.22.21.2","libirs1601":"9.16.6-150300.22.21.2","libisc1606":"9.16.6-150300.22.21.2","libisccfg1600":"9.16.6-150300.22.21.2","libbind9-1600":"9.16.6-150300.22.21.2","libirs-devel":"9.16.6-150300.22.21.2","libisccc1600":"9.16.6-150300.22.21.2","libns1604":"9.16.6-150300.22.21.2"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3682-1.json"}}],"schema_version":"1.7.5"}