CVE-2022-2906
Estado: ModificadaAlta (7.5)—
An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.05%
- Percentil entre todas las CVEs puntuadas: 81
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-401
- CWE-401
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-2906",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-2906",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-05-28T15:25:54.428926Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-officer@isc.org",
"affectedData": [
{
"vendor": "ISC",
"product": "BIND9",
"versions": [
{
"status": "affected",
"version": "Open Source Branch 9.18 9.18.0 through versions before 9.18.7"
},
{
"status": "affected",
"version": "Development Branch 9.19 9.19.0 through versions before 9.19.5"
}
]
}
]
}
],
"published": "2022-09-21T11:15:09.620",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2022/09/21/3",
"tags": [
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "https://kb.isc.org/docs/cve-2022-2906",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "https://security.gentoo.org/glsa/202210-25",
"tags": [
"Third Party Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2022/09/21/3",
"tags": [
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://kb.isc.org/docs/cve-2022-2906",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/202210-25",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-401"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service."
},
{
"lang": "es",
"value": "Un atacante puede aprovechar este fallo para erosionar gradualmente la memoria disponible hasta el punto de que named sea bloqueado por falta de recursos. Al reiniciar, el atacante tendría que empezar de nuevo, pero sin embargo se presenta la posibilidad de denegar el servicio"
}
],
"lastModified": "2026-06-17T04:42:48.440",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAE4B411-40F7-422D-8A5C-775ED1D00189",
"versionEndExcluding": "9.18.7",
"versionStartIncluding": "9.18.0"
},
{
"criteria": "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E1EC206-AC11-4A7E-9723-C4F69FF76892",
"versionEndExcluding": "9.19.5",
"versionStartIncluding": "9.19.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-officer@isc.org"
}