VDB
ALPINE-CVE-2023-50868
ALPINE-CVE-2023-50868
PUBLISHED
CVSS 7.5 HIGH
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.17 | bind | 9.10.1-r0, 9.10.0, 9.10.0 |
| Alpine:v3.21 | bind | 9.9.3_p2-r1, 9.10.0-r0, 9.10.0_p1-r0 |
| Alpine:v3.18 | unbound | 1.4.13-r3, 1.4.13-r2, 1.4.13-r1 |
| Alpine:v3.20 | bind | 9.10.2-r1, 9.10.2_p3-r0, 9.10.2_p3-r1 |
| Alpine:v3.21 | unbound | 1.9.6-r0, 0, 1.10.0-r0 |
| Alpine:v3.23 | dnsmasq | 0, 2.86-r0, 2.86-r1 |
| Alpine:v3.23 | unbound | 1.18.0-r0, 1.5.6-r3, 1.5.6-r4 |
| Alpine:v3.17 | dnsmasq | 0, 2.86-r0, 2.86-r1 |
| Alpine:v3.20 | dnsmasq | 0, 0, 0 |
| Alpine:v3.19 | dnsmasq | 2.86-r2, 2.86-r2, 2.86-r1 |
| Alpine:v3.23 | bind | 9.7.0_p1-r1, 0, 9.10.0_p2-r0 |
| Alpine:v3.24 | bind | 9.0.0, 9.0.0, 9.0.0 |
| Alpine:v3.16 | bind | 9.6.1, 9.6.1, 9.6.1 |
| Alpine:v3.21 | dnsmasq | 2.86-r1, 2.86-r3, 2.86-r4 |
| Alpine:v3.17 | unbound | 1.8.0-r0, 0, 1.10.0-r0 |
| Alpine:v3.19 | bind | 9.10.0_p2-r1, 9.10.0_p1-r0, * |
| Alpine:v3.22 | dnsmasq | 0, 0, 0 |
| Alpine:v3.22 | bind | 9.9.3_p2-r2, 9.9.1_p2-r0, 9.9.1_p3-r0 |
| Alpine:v3.24 | dnsmasq | 0, 0, 0 |
| Alpine:v3.20 | unbound | 1.9.5-r2, 1.9.6-r0, 1.9.5-r1 |
…and 5 more
Timeline
- Feb 14, 2024 CVE Published
- Aug 7, 2026 CVE Updated
- Aug 8, 2026 Distribution Patch