CVE-2022-1183 - log back

CVE-2022-1183 edited at 18 May 2022 23:56:19
Type
- Unknown
+ Incorrect calculation
CVE-2022-1183 created at 18 May 2022 23:53:44
Severity
+ High
Remote
+ Remote
Type
+ Unknown
Description
+ An assertion failure can be triggered if a TLS connection to a configured http TLS listener with a defined endpoint is destroyed too early.
+
+ On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected.
References
+ https://kb.isc.org/v1/docs/cve-2022-1183
Notes
+ Arch Linux's default configuration is not vulnerable.