KeyTrap attack: Internet access disrupted with one DNS packet
ID: 6fc2d253-a7ee-5b46-bced-6a5ecfcb7de8
STIX ID: report--6fc2d253-a7ee-5b46-bced-6a5ecfcb7de8
Feed Name: Bleeping Computer
KeyTrap (CVE-2023-50387) is a decades-old DNSSEC design flaw that enables algorithmic complexity attacks: a single crafted DNS packet can force resolvers to process excessive cryptographic keys and signatures (up to a ~2 million× increase in CPU instructions), stalling DNS resolution for between roughly one minute and many hours. Discovered and disclosed by ATHENE researchers, the issue affects many popular DNS implementations and services; major providers have applied mitigations, but researchers warn addressing the root cause may require rethinking DNSSEC validation design.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
