'KeyTrap' DNS Bug Threatens Widespread Internet Outages
ID: b11dee23-f5ca-5ce9-ab18-b7974acddb90
STIX ID: report--b11dee23-f5ca-5ce9-ab18-b7974acddb90
Feed Name: Dark Reading
Researchers at ATHENE disclosed "KeyTrap" (CVE-2023-50387), a DNSSEC design flaw that can induce algorithmic complexity attacks causing DNS resolvers — including widely deployed BIND 9 — to enter resource-consuming resolution loops and stall, potentially producing widespread Internet outages; vendors and major DNS providers have released temporary patches and ISC recommends installing patched BIND versions, while the research team works on a permanent redesign and no active exploitation has been observed so far.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
