Vulnerability Details CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.267
EPSS Ranking 96.1%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2023-50387
-
-
-
-
-
-
-
-
cpe:2.3:a:isc:bind:9.11.29
-
cpe:2.3:a:isc:bind:9.11.31
-
cpe:2.3:a:isc:bind:9.11.35
-
cpe:2.3:a:isc:bind:9.11.36
-
cpe:2.3:a:isc:bind:9.12.0
-
cpe:2.3:a:isc:bind:9.16.0
-
cpe:2.3:a:isc:bind:9.16.12
-
cpe:2.3:a:isc:bind:9.16.13
-
cpe:2.3:a:isc:bind:9.16.15
-
cpe:2.3:a:isc:bind:9.16.19
-
cpe:2.3:a:isc:bind:9.16.21
-
cpe:2.3:a:isc:bind:9.16.22
-
cpe:2.3:a:isc:bind:9.16.36
-
cpe:2.3:a:isc:bind:9.16.37
-
cpe:2.3:a:isc:bind:9.16.43
-
cpe:2.3:a:isc:bind:9.16.44
-
cpe:2.3:a:isc:bind:9.16.45
-
cpe:2.3:a:isc:bind:9.18.0
-
cpe:2.3:a:isc:bind:9.18.1
-
cpe:2.3:a:isc:bind:9.18.10
-
cpe:2.3:a:isc:bind:9.18.11
-
cpe:2.3:a:isc:bind:9.18.18
-
cpe:2.3:a:isc:bind:9.18.19
-
cpe:2.3:a:isc:bind:9.18.2
-
cpe:2.3:a:isc:bind:9.18.3
-
cpe:2.3:a:isc:bind:9.18.4
-
cpe:2.3:a:isc:bind:9.18.5
-
cpe:2.3:a:isc:bind:9.18.6
-
cpe:2.3:a:isc:bind:9.18.7
-
cpe:2.3:a:isc:bind:9.18.8
-
cpe:2.3:a:isc:bind:9.19.0
-
cpe:2.3:a:isc:bind:9.19.1
-
cpe:2.3:a:isc:bind:9.19.16
-
cpe:2.3:a:isc:bind:9.19.17
-
cpe:2.3:a:isc:bind:9.19.2
-
cpe:2.3:a:isc:bind:9.19.3
-
cpe:2.3:a:isc:bind:9.19.4
-
cpe:2.3:a:isc:bind:9.19.5
-
cpe:2.3:a:isc:bind:9.19.6
-
cpe:2.3:a:isc:bind:9.19.8
-
cpe:2.3:a:isc:bind:9.19.9
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:nic:knot_resolver:-
-
cpe:2.3:a:nic:knot_resolver:1.0.0
-
cpe:2.3:a:nic:knot_resolver:1.1.0
-
cpe:2.3:a:nic:knot_resolver:1.1.1
-
cpe:2.3:a:nic:knot_resolver:1.2.0
-
cpe:2.3:a:nic:knot_resolver:1.2.1
-
cpe:2.3:a:nic:knot_resolver:1.2.2
-
cpe:2.3:a:nic:knot_resolver:1.2.3
-
cpe:2.3:a:nic:knot_resolver:1.2.4
-
cpe:2.3:a:nic:knot_resolver:1.2.5
-
cpe:2.3:a:nic:knot_resolver:1.2.6
-
cpe:2.3:a:nic:knot_resolver:1.3.0
-
cpe:2.3:a:nic:knot_resolver:1.3.1
-
cpe:2.3:a:nic:knot_resolver:1.3.2
-
cpe:2.3:a:nic:knot_resolver:1.3.3
-
cpe:2.3:a:nic:knot_resolver:1.4.0
-
cpe:2.3:a:nic:knot_resolver:1.5.0
-
cpe:2.3:a:nic:knot_resolver:1.5.1
-
cpe:2.3:a:nic:knot_resolver:1.5.2
-
cpe:2.3:a:nic:knot_resolver:1.5.3
-
cpe:2.3:a:nic:knot_resolver:1.99.1
-
cpe:2.3:a:nic:knot_resolver:2.0.0
-
cpe:2.3:a:nic:knot_resolver:2.1.0
-
cpe:2.3:a:nic:knot_resolver:2.1.1
-
cpe:2.3:a:nic:knot_resolver:2.2.0
-
cpe:2.3:a:nic:knot_resolver:2.3.0
-
cpe:2.3:a:nic:knot_resolver:2.4.0
-
cpe:2.3:a:nic:knot_resolver:2.4.1
-
cpe:2.3:a:nic:knot_resolver:3.0.0
-
cpe:2.3:a:nic:knot_resolver:3.1.0
-
cpe:2.3:a:nic:knot_resolver:3.2.0
-
cpe:2.3:a:nic:knot_resolver:3.2.1
-
cpe:2.3:a:nic:knot_resolver:4.0.0
-
cpe:2.3:a:nic:knot_resolver:4.1.0
-
cpe:2.3:a:nic:knot_resolver:4.2.0
-
cpe:2.3:a:nic:knot_resolver:4.2.1
-
cpe:2.3:a:nic:knot_resolver:4.2.2
-
cpe:2.3:a:nic:knot_resolver:4.3.0
-
cpe:2.3:a:nic:knot_resolver:5.0.0
-
cpe:2.3:a:nic:knot_resolver:5.0.1
-
cpe:2.3:a:nic:knot_resolver:5.1.1
-
cpe:2.3:a:nic:knot_resolver:5.5.1
-
cpe:2.3:a:nic:knot_resolver:5.6.0
-
cpe:2.3:a:nlnetlabs:unbound:-
-
cpe:2.3:a:nlnetlabs:unbound:0.0
-
cpe:2.3:a:nlnetlabs:unbound:0.1
-
cpe:2.3:a:nlnetlabs:unbound:0.10
-
cpe:2.3:a:nlnetlabs:unbound:0.11
-
cpe:2.3:a:nlnetlabs:unbound:0.2
-
cpe:2.3:a:nlnetlabs:unbound:0.3
-
cpe:2.3:a:nlnetlabs:unbound:0.4
-
cpe:2.3:a:nlnetlabs:unbound:0.5
-
cpe:2.3:a:nlnetlabs:unbound:0.6
-
cpe:2.3:a:nlnetlabs:unbound:0.7
-
cpe:2.3:a:nlnetlabs:unbound:0.7.1
-
cpe:2.3:a:nlnetlabs:unbound:0.7.2
-
cpe:2.3:a:nlnetlabs:unbound:0.8
-
cpe:2.3:a:nlnetlabs:unbound:0.9
-
cpe:2.3:a:nlnetlabs:unbound:1.0.0
-
cpe:2.3:a:nlnetlabs:unbound:1.0.1
-
cpe:2.3:a:nlnetlabs:unbound:1.0.2
-
cpe:2.3:a:nlnetlabs:unbound:1.1.0
-
cpe:2.3:a:nlnetlabs:unbound:1.1.1
-
cpe:2.3:a:nlnetlabs:unbound:1.10.0
-
cpe:2.3:a:nlnetlabs:unbound:1.10.1
-
cpe:2.3:a:nlnetlabs:unbound:1.11.0
-
cpe:2.3:a:nlnetlabs:unbound:1.12.0
-
cpe:2.3:a:nlnetlabs:unbound:1.13.0
-
cpe:2.3:a:nlnetlabs:unbound:1.13.1
-
cpe:2.3:a:nlnetlabs:unbound:1.13.2
-
cpe:2.3:a:nlnetlabs:unbound:1.14.0
-
cpe:2.3:a:nlnetlabs:unbound:1.15.0
-
cpe:2.3:a:nlnetlabs:unbound:1.16.0
-
cpe:2.3:a:nlnetlabs:unbound:1.16.1
-
cpe:2.3:a:nlnetlabs:unbound:1.16.2
-
cpe:2.3:a:nlnetlabs:unbound:1.16.3
-
cpe:2.3:a:nlnetlabs:unbound:1.17.0
-
cpe:2.3:a:nlnetlabs:unbound:1.17.1
-
cpe:2.3:a:nlnetlabs:unbound:1.18.0
-
cpe:2.3:a:nlnetlabs:unbound:1.19.0
-
cpe:2.3:a:nlnetlabs:unbound:1.2.0
-
cpe:2.3:a:nlnetlabs:unbound:1.2.1
-
cpe:2.3:a:nlnetlabs:unbound:1.3.0
-
cpe:2.3:a:nlnetlabs:unbound:1.3.1
-
cpe:2.3:a:nlnetlabs:unbound:1.3.2
-
cpe:2.3:a:nlnetlabs:unbound:1.3.3
-
cpe:2.3:a:nlnetlabs:unbound:1.3.4
-
cpe:2.3:a:nlnetlabs:unbound:1.4.0
-
cpe:2.3:a:nlnetlabs:unbound:1.4.1
-
cpe:2.3:a:nlnetlabs:unbound:1.4.10
-
cpe:2.3:a:nlnetlabs:unbound:1.4.11
-
cpe:2.3:a:nlnetlabs:unbound:1.4.13
-
cpe:2.3:a:nlnetlabs:unbound:1.4.14
-
cpe:2.3:a:nlnetlabs:unbound:1.4.15
-
cpe:2.3:a:nlnetlabs:unbound:1.4.16
-
cpe:2.3:a:nlnetlabs:unbound:1.4.17
-
cpe:2.3:a:nlnetlabs:unbound:1.4.18
-
cpe:2.3:a:nlnetlabs:unbound:1.4.19
-
cpe:2.3:a:nlnetlabs:unbound:1.4.2
-
cpe:2.3:a:nlnetlabs:unbound:1.4.20
-
cpe:2.3:a:nlnetlabs:unbound:1.4.21
-
cpe:2.3:a:nlnetlabs:unbound:1.4.22
-
cpe:2.3:a:nlnetlabs:unbound:1.4.3
-
cpe:2.3:a:nlnetlabs:unbound:1.4.4
-
cpe:2.3:a:nlnetlabs:unbound:1.4.5
-
cpe:2.3:a:nlnetlabs:unbound:1.4.6
-
cpe:2.3:a:nlnetlabs:unbound:1.4.7
-
cpe:2.3:a:nlnetlabs:unbound:1.4.8
-
cpe:2.3:a:nlnetlabs:unbound:1.4.9
-
cpe:2.3:a:nlnetlabs:unbound:1.5.0
-
cpe:2.3:a:nlnetlabs:unbound:1.5.1
-
cpe:2.3:a:nlnetlabs:unbound:1.5.10
-
cpe:2.3:a:nlnetlabs:unbound:1.5.2
-
cpe:2.3:a:nlnetlabs:unbound:1.5.3
-
cpe:2.3:a:nlnetlabs:unbound:1.5.4
-
cpe:2.3:a:nlnetlabs:unbound:1.5.5
-
cpe:2.3:a:nlnetlabs:unbound:1.5.6
-
cpe:2.3:a:nlnetlabs:unbound:1.5.6rc1
-
cpe:2.3:a:nlnetlabs:unbound:1.5.7
-
cpe:2.3:a:nlnetlabs:unbound:1.5.8
-
cpe:2.3:a:nlnetlabs:unbound:1.5.9
-
cpe:2.3:a:nlnetlabs:unbound:1.6.0
-
cpe:2.3:a:nlnetlabs:unbound:1.6.1
-
cpe:2.3:a:nlnetlabs:unbound:1.6.2
-
cpe:2.3:a:nlnetlabs:unbound:1.6.3
-
cpe:2.3:a:nlnetlabs:unbound:1.6.4
-
cpe:2.3:a:nlnetlabs:unbound:1.6.5
-
cpe:2.3:a:nlnetlabs:unbound:1.6.6
-
cpe:2.3:a:nlnetlabs:unbound:1.6.6-5
-
cpe:2.3:a:nlnetlabs:unbound:1.6.7
-
cpe:2.3:a:nlnetlabs:unbound:1.6.8
-
cpe:2.3:a:nlnetlabs:unbound:1.7.0
-
cpe:2.3:a:nlnetlabs:unbound:1.7.1
-
cpe:2.3:a:nlnetlabs:unbound:1.7.2
-
cpe:2.3:a:nlnetlabs:unbound:1.7.3
-
cpe:2.3:a:nlnetlabs:unbound:1.8.0
-
cpe:2.3:a:nlnetlabs:unbound:1.8.1
-
cpe:2.3:a:nlnetlabs:unbound:1.8.2
-
cpe:2.3:a:nlnetlabs:unbound:1.8.3
-
cpe:2.3:a:nlnetlabs:unbound:1.9.0
-
cpe:2.3:a:nlnetlabs:unbound:1.9.2
-
cpe:2.3:a:nlnetlabs:unbound:1.9.3
-
cpe:2.3:a:nlnetlabs:unbound:1.9.4
-
cpe:2.3:a:nlnetlabs:unbound:1.9.5
-
cpe:2.3:a:nlnetlabs:unbound:1.9.6
-
cpe:2.3:a:powerdns:recursor:*
-
cpe:2.3:a:powerdns:recursor:4.8.0
-
cpe:2.3:a:powerdns:recursor:4.8.1
-
cpe:2.3:a:powerdns:recursor:4.8.2
-
cpe:2.3:a:powerdns:recursor:4.8.3
-
cpe:2.3:a:powerdns:recursor:4.8.4
-
cpe:2.3:a:thekelleys:dnsmasq:-
-
cpe:2.3:a:thekelleys:dnsmasq:0.4
-
cpe:2.3:a:thekelleys:dnsmasq:0.5
-
cpe:2.3:a:thekelleys:dnsmasq:0.6
-
cpe:2.3:a:thekelleys:dnsmasq:0.7
-
cpe:2.3:a:thekelleys:dnsmasq:0.95
-
cpe:2.3:a:thekelleys:dnsmasq:0.96
-
cpe:2.3:a:thekelleys:dnsmasq:0.98
-
cpe:2.3:a:thekelleys:dnsmasq:0.992
-
cpe:2.3:a:thekelleys:dnsmasq:0.996
-
cpe:2.3:a:thekelleys:dnsmasq:1.0
-
cpe:2.3:a:thekelleys:dnsmasq:1.10
-
cpe:2.3:a:thekelleys:dnsmasq:1.11
-
cpe:2.3:a:thekelleys:dnsmasq:1.12
-
cpe:2.3:a:thekelleys:dnsmasq:1.13
-
cpe:2.3:a:thekelleys:dnsmasq:1.14
-
cpe:2.3:a:thekelleys:dnsmasq:1.15
-
cpe:2.3:a:thekelleys:dnsmasq:1.16
-
cpe:2.3:a:thekelleys:dnsmasq:1.17
-
cpe:2.3:a:thekelleys:dnsmasq:1.18
-
cpe:2.3:a:thekelleys:dnsmasq:1.2
-
cpe:2.3:a:thekelleys:dnsmasq:1.3
-
cpe:2.3:a:thekelleys:dnsmasq:1.4
-
cpe:2.3:a:thekelleys:dnsmasq:1.5
-
cpe:2.3:a:thekelleys:dnsmasq:1.6
-
cpe:2.3:a:thekelleys:dnsmasq:1.7
-
cpe:2.3:a:thekelleys:dnsmasq:1.8
-
cpe:2.3:a:thekelleys:dnsmasq:1.9
-
cpe:2.3:a:thekelleys:dnsmasq:2.0
-
cpe:2.3:a:thekelleys:dnsmasq:2.1
-
cpe:2.3:a:thekelleys:dnsmasq:2.10
-
cpe:2.3:a:thekelleys:dnsmasq:2.11
-
cpe:2.3:a:thekelleys:dnsmasq:2.12
-
cpe:2.3:a:thekelleys:dnsmasq:2.13
-
cpe:2.3:a:thekelleys:dnsmasq:2.14
-
cpe:2.3:a:thekelleys:dnsmasq:2.15
-
cpe:2.3:a:thekelleys:dnsmasq:2.16
-
cpe:2.3:a:thekelleys:dnsmasq:2.17
-
cpe:2.3:a:thekelleys:dnsmasq:2.18
-
cpe:2.3:a:thekelleys:dnsmasq:2.19
-
cpe:2.3:a:thekelleys:dnsmasq:2.2
-
cpe:2.3:a:thekelleys:dnsmasq:2.20
-
cpe:2.3:a:thekelleys:dnsmasq:2.21
-
cpe:2.3:a:thekelleys:dnsmasq:2.22
-
cpe:2.3:a:thekelleys:dnsmasq:2.23
-
cpe:2.3:a:thekelleys:dnsmasq:2.24
-
cpe:2.3:a:thekelleys:dnsmasq:2.25
-
cpe:2.3:a:thekelleys:dnsmasq:2.26
-
cpe:2.3:a:thekelleys:dnsmasq:2.27
-
cpe:2.3:a:thekelleys:dnsmasq:2.28
-
cpe:2.3:a:thekelleys:dnsmasq:2.29
-
cpe:2.3:a:thekelleys:dnsmasq:2.3
-
cpe:2.3:a:thekelleys:dnsmasq:2.30
-
cpe:2.3:a:thekelleys:dnsmasq:2.31
-
cpe:2.3:a:thekelleys:dnsmasq:2.33
-
cpe:2.3:a:thekelleys:dnsmasq:2.34
-
cpe:2.3:a:thekelleys:dnsmasq:2.35
-
cpe:2.3:a:thekelleys:dnsmasq:2.36
-
cpe:2.3:a:thekelleys:dnsmasq:2.37
-
cpe:2.3:a:thekelleys:dnsmasq:2.38
-
cpe:2.3:a:thekelleys:dnsmasq:2.39
-
cpe:2.3:a:thekelleys:dnsmasq:2.4
-
cpe:2.3:a:thekelleys:dnsmasq:2.40
-
cpe:2.3:a:thekelleys:dnsmasq:2.41
-
cpe:2.3:a:thekelleys:dnsmasq:2.42
-
cpe:2.3:a:thekelleys:dnsmasq:2.43
-
cpe:2.3:a:thekelleys:dnsmasq:2.44
-
cpe:2.3:a:thekelleys:dnsmasq:2.45
-
cpe:2.3:a:thekelleys:dnsmasq:2.46
-
cpe:2.3:a:thekelleys:dnsmasq:2.47
-
cpe:2.3:a:thekelleys:dnsmasq:2.48
-
cpe:2.3:a:thekelleys:dnsmasq:2.49
-
cpe:2.3:a:thekelleys:dnsmasq:2.5
-
cpe:2.3:a:thekelleys:dnsmasq:2.50
-
cpe:2.3:a:thekelleys:dnsmasq:2.51
-
cpe:2.3:a:thekelleys:dnsmasq:2.52
-
cpe:2.3:a:thekelleys:dnsmasq:2.53
-
cpe:2.3:a:thekelleys:dnsmasq:2.54
-
cpe:2.3:a:thekelleys:dnsmasq:2.55
-
cpe:2.3:a:thekelleys:dnsmasq:2.56
-
cpe:2.3:a:thekelleys:dnsmasq:2.57
-
cpe:2.3:a:thekelleys:dnsmasq:2.58
-
cpe:2.3:a:thekelleys:dnsmasq:2.59
-
cpe:2.3:a:thekelleys:dnsmasq:2.6
-
cpe:2.3:a:thekelleys:dnsmasq:2.60
-
cpe:2.3:a:thekelleys:dnsmasq:2.61
-
cpe:2.3:a:thekelleys:dnsmasq:2.62
-
cpe:2.3:a:thekelleys:dnsmasq:2.63
-
cpe:2.3:a:thekelleys:dnsmasq:2.64
-
cpe:2.3:a:thekelleys:dnsmasq:2.65
-
cpe:2.3:a:thekelleys:dnsmasq:2.66
-
cpe:2.3:a:thekelleys:dnsmasq:2.67
-
cpe:2.3:a:thekelleys:dnsmasq:2.68
-
cpe:2.3:a:thekelleys:dnsmasq:2.69
-
cpe:2.3:a:thekelleys:dnsmasq:2.7
-
cpe:2.3:a:thekelleys:dnsmasq:2.70
-
cpe:2.3:a:thekelleys:dnsmasq:2.71
-
cpe:2.3:a:thekelleys:dnsmasq:2.72
-
cpe:2.3:a:thekelleys:dnsmasq:2.73
-
cpe:2.3:a:thekelleys:dnsmasq:2.74
-
cpe:2.3:a:thekelleys:dnsmasq:2.75
-
cpe:2.3:a:thekelleys:dnsmasq:2.76
-
cpe:2.3:a:thekelleys:dnsmasq:2.77
-
cpe:2.3:a:thekelleys:dnsmasq:2.78
-
cpe:2.3:a:thekelleys:dnsmasq:2.79
-
cpe:2.3:a:thekelleys:dnsmasq:2.8
-
cpe:2.3:a:thekelleys:dnsmasq:2.80
-
cpe:2.3:a:thekelleys:dnsmasq:2.81
-
cpe:2.3:a:thekelleys:dnsmasq:2.82
-
cpe:2.3:a:thekelleys:dnsmasq:2.83
-
cpe:2.3:a:thekelleys:dnsmasq:2.84
-
cpe:2.3:a:thekelleys:dnsmasq:2.85
-
cpe:2.3:a:thekelleys:dnsmasq:2.86
-
cpe:2.3:a:thekelleys:dnsmasq:2.87
-
cpe:2.3:a:thekelleys:dnsmasq:2.88
-
cpe:2.3:a:thekelleys:dnsmasq:2.89
-
cpe:2.3:a:thekelleys:dnsmasq:2.9
-
cpe:2.3:o:fedoraproject:fedora:39
-
cpe:2.3:o:microsoft:windows_server_2008:r2
-
cpe:2.3:o:microsoft:windows_server_2012:-
-
cpe:2.3:o:microsoft:windows_server_2012:r2
-
cpe:2.3:o:microsoft:windows_server_2016:-
-
cpe:2.3:o:microsoft:windows_server_2019:-
-
cpe:2.3:o:microsoft:windows_server_2022:-
-
cpe:2.3:o:microsoft:windows_server_2022_23h2:-
-
cpe:2.3:o:redhat:enterprise_linux:6.0
-
cpe:2.3:o:redhat:enterprise_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0
-
cpe:2.3:o:redhat:enterprise_linux:9.0