{"id":"UBUNTU-CVE-2022-3924","details":"This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient clients already waiting when a new client query is received so that it is necessary to SERVFAIL the longest waiting client (see BIND 9 ARM `recursive-clients` limit and soft quota), then it is possible for a race to occur between providing a stale answer to this older client and sending an early timeout SERVFAIL, which may cause an assertion failure. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.","modified":"2026-04-22T13:27:50.752473Z","published":"2023-01-25T00:00:00Z","related":["USN-5827-1"],"upstream":["CVE-2022-3924"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3924"},{"type":"REPORT","url":"https://kb.isc.org/docs/cve-2022-3924"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5827-1"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-3924"}],"affected":[{"package":{"name":"bind9","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/bind9@1:9.18.1-1ubuntu1.3?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:9.18.1-1ubuntu1.3"}]}],"versions":["1:9.16.15-1ubuntu1","1:9.16.15-1ubuntu2","1:9.16.15-1ubuntu3","1:9.18.0-2ubuntu1","1:9.18.0-2ubuntu2","1:9.18.0-2ubuntu3","1:9.18.1-1ubuntu1","1:9.18.1-1ubuntu1.1","1:9.18.1-1ubuntu1.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"bind9","binary_version":"1:9.18.1-1ubuntu1.3"},{"binary_name":"bind9-dnsutils","binary_version":"1:9.18.1-1ubuntu1.3"},{"binary_name":"bind9-host","binary_version":"1:9.18.1-1ubuntu1.3"},{"binary_name":"bind9-libs","binary_version":"1:9.18.1-1ubuntu1.3"},{"binary_name":"bind9-utils","binary_version":"1:9.18.1-1ubuntu1.3"},{"binary_version":"1:9.18.1-1ubuntu1.3","binary_name":"bind9utils"},{"binary_name":"dnsutils","binary_version":"1:9.18.1-1ubuntu1.3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-3924.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}