- ------------------------------------------------------------------------- Debian LTS Advisory DLA-3139-1 [email protected] https://www.debian.org/lts/security/ Chris Lamb October 07, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : knot-resolver Version : 3.2.1-3+deb10u1 CVE ID : CVE-2022-40188 It was discovered that there was a potential remote denial-of-service vulnerability in the knot-resolver DNSSEC-validating DNS resolver. Remote attackers could have caused a denial of service via CPU consumption by exploiting algorithmic complexity: during an attack, an authoritative server would return large nameserver or address sets. For Debian 10 buster, this problem has been fixed in version 3.2.1-3+deb10u1. We recommend that you upgrade your knot-resolver packages. For the detailed security status of knot-resolver please refer to its security tracker page at: https://security-tracker.debian.org/tracker/knot-resolver Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS