VDB

ALPINE-CVE-2022-2906

ALPINE-CVE-2022-2906 PUBLISHED CVSS 7.5 HIGH

An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.23bind9.16.17-r2, 9.9.5-r0, 9.9.4
Alpine:v3.19bind9.9.1_p1-r0, 9.9.5-r0, 9.9.4
Alpine:v3.17bind9.16.20-r4, 9.9.5-r0, 9.9.4
Alpine:v3.16bind9.9.1_p3-r0, 0, 9.10.0-r0
Alpine:v3.18bind*, 9.16.5-r0, 9.16.22-r5
Alpine:v3.15bind9.14.12-r0, 9.10.4_p1-r0, 9.10.4-r0
Alpine:v3.20bind9.10.1-r1, 9.10.1-r2, 9.10.1_p1-r0
Alpine:v3.14bind9.7.2_p1-r0, 0, 9.10.0-r0
Alpine:v3.13bind*, 9.11.1-r0, 9.10.1-r2
Alpine:v3.21bind9.10.0-r0, 0, 9.9.2-r0
Alpine:v3.22bind0, 9.10.0-r0, 9.10.0_p2-r0

Timeline

  • Sep 21, 2022 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›