VDB

ALPINE-CVE-2022-2906

ALPINE-CVE-2022-2906 PUBLISHED CVSS 7.5 HIGH

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.24bind9.18.0
Alpine:v3.23bind9.9.5-r0, 9.9.4, 9.9.4
Alpine:v3.19bind9.9.1_p1-r0, 9.18.0, 9.9.5-r0
Alpine:v3.17bind9.18.0, 9.9.5-r0, 9.9.4
Alpine:v3.16bind9.9.1_p3-r0, 0, 9.10.0-r0
Alpine:v3.18bind*, 9.16.5-r0, 9.16.22-r5
Alpine:v3.15bind9.14.12-r0, 9.10.4_p1-r0, 9.10.4-r0
Alpine:v3.20bind9.10.1-r1, 9.10.1-r2, 9.10.1_p1-r0
Alpine:v3.14bind9.7.2-r0, 0, 9.10.0-r0
Alpine:v3.13bind*, 9.11.1-r0, 9.10.1-r2
Alpine:v3.21bind9.10.0-r0, 0, 9.9.2-r0
Alpine:v3.22bind0, 9.10.0-r0, 9.10.0_p2-r0

Timeline

  • Sep 21, 2022 CVE Published
  • Apr 30, 2026 Distribution Patch
  • Jul 8, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›