Denial of Service Vulnerability in Knot Resolver by NIC.cz
CVE-2022-40188
7.5HIGH
What is CVE-2022-40188?
Knot Resolver, prior to version 5.5.3, is susceptible to a denial of service attack due to its handling of large NS sets or address sets. Attackers can exploit this vulnerability by causing excessive CPU consumption, leading to a degradation of service. This issue stems from the algorithmic complexity involved during the resolution process and presents a significant risk for environments relying on Knot Resolver for DNS functionalities.
