debian · CVE-2023-50868

Quick triage

Priority: end-of-life 公開: Updated: Mon, 20 Jul 2026 12:32:35 GMT

参照: Official debian advisory, NVD, CVE.org · CVE 詳細

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2023-50868 end-of-life priority: Debian including 7 source packages (bind9, dnsjava, …), 35 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 31, open 4.

Description:

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

cvelogic Threat Intelligence