---
cve: "CVE-2023-50868"
severity: "HIGH"
cvss: 7.5
epss: "81.7%"
vendor: "n/a"
kev: false
exploited: false
published: "2024-02-14 16:15:45"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T09:59:18+02:00"
---

# CVE-2023-50868

> 7.5 HIGH

## Beschreibung

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Keine | good |

## Patch verfügbar (OSV)

- 0dab57e15f7d02d8b0c9bff513fe1c735f499322 (Commit)
- 0dab57e15f7d02d8b0c9bff513fe1c735f499322 (Commit)

## Referenzen

- <https://nlnetlabs.nl/news/2024/Feb/13/unbound-1.19.1-released/>
- <https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2024-01.html>
- <https://www.isc.org/blogs/2024-bind-security-release/>
- <https://datatracker.ietf.org/doc/html/rfc5155>
- <https://kb.isc.org/docs/cve-2023-50868>
- <https://gitlab.nic.cz/knot/knot-resolver/-/releases/v5.7.1>
- <https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2024q1/017430.html>
- <https://access.redhat.com/security/cve/CVE-2023-50868>
- <https://bugzilla.suse.com/show_bug.cgi?id=1219826>
- <http://www.openwall.com/lists/oss-security/2024/02/16/2>
- <http://www.openwall.com/lists/oss-security/2024/02/16/3>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVYA42BLXUCIDLD35YIJPJSHDIADNYMP/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BUIP7T7Z4T3UHLXFWG6XIVDP4GYPD3AI/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNNHZSZPG2E7NBMBNYPGHCFI4V4XRWNQ/>
- <https://lists.debian.org/debian-lts-announce/2024/02/msg00006.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-50868) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
