TCP Reconnections Issue in Knot Resolver by NIC.cz
CVE-2023-46317

7.5HIGH

Key Information:

Vendor

Nic

Vendor
CVE Published:
22 October 2023

What is CVE-2023-46317?

Knot Resolver versions before 5.7.0 exhibit a vulnerability that causes excessive TCP reconnections upon receiving nonsensical responses from DNS servers. This behavior can lead to performance degradation and increased latency in DNS resolutions, potentially impacting network functionality and user experience.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.