﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
17109	bind-9.18.7 bind9	Douglas R. Reno	Bruce Dubbs	"New point version

I know of 6 CVEs in this one - 4 high, and 2 medium, and all are remotely exploitable:


- CVE-2022-2795:	Processing large delegations may severely degrade resolver performance https://kb.isc.org/docs/cve-2022-2795

- CVE-2022-2881:	Buffer overread in statistics channel code https://kb.isc.org/docs/cve-2022-2881

- CVE-2022-2906:	Memory leaks in code handling Diffie-Hellman key exchange via TKEY RRs (OpenSSL 3.0.0+ only) https://kb.isc.org/docs/cve-2022-2906

- CVE-2022-3080:	BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly https://kb.isc.org/docs/cve-2022-3080

- CVE-2022-38177:	Memory leak in ECDSA DNSSEC verification code https://kb.isc.org/docs/cve-2022-38177

- CVE-2022-38178:	Memory leaks in EdDSA DNSSEC verification code https://kb.isc.org/docs/cve-2022-38178"	enhancement	closed	elevated	11.3	BOOK	git	medium	fixed		
