Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE 12-SP3 Important: Bind Memory Leak and Performance Issue Fix

suse
Calendar Grey October 4, 2022
Dist Suse Esm H88
New release addressing bind configuration optimizations and resource efficiency in SUSE Linux, featuring critical updates.
An update that fixes two vulnerabilities is now available

Summary

This update for bind fixes the following issues: - CVE-2022-2795: Fixed potential performance degredation due to missing database lookup limits when processing large delegations (bsc#1203614). - CVE-2022-38177: Fixed a memory leak that could be externally triggered in the DNSSEC verification code for the ECDSA algorithm (bsc#1203619). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2022-3500=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-3500=1 Package List:

References

#1203614 #1203619

Cross- CVE-2022-2795 CVE-2022-38177

CVSS scores:

CVE-2022-2795 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-2795 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CVE-2022-38177 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-38177 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products:

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Linux Enterprise Server 12-SP3-BCL

https://www.suse.com/security/cve/CVE-2022-2795.html

https://www.suse.com/security/cve/CVE-2022-38177.html

https://bugzilla.suse.com/1203614

https://bugzilla.suse.com/1203619

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3500-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here