Vulnerability record · CVE-2023-50387 · published 14 February 2024
CVE-2023-50387: DNSSEC KeyTrap flaw in DNS resolvers causes CPU exhaustion DoS
Redhat · Enterprise Linux
CVE-2023-50387, known as KeyTrap, is a flaw in DNSSEC validation logic where a zone containing many DNSKEY and RRSIG records forces resolvers to evaluate all algorithm combinations, consuming excessive CPU. It affects multiple DNS resolver implementations including BIND, Unbound, PowerDNS Recursor, Knot Resolver, dnsmasq, and Windows Server DNS. Because DNSSEC validation is widely deployed, a single crafted response can stall or take down a resolver, disrupting name resolution for all clients behind it.
Description
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 and an EPSS near 1.0 indicate a remotely exploitable, high-likelihood denial-of-service flaw affecting widely deployed DNS resolvers, though it is not in KEV and causes availability loss only.
What it is
CVE-2023-50387, known as KeyTrap, is a flaw in DNSSEC validation logic where a zone containing many DNSKEY and RRSIG records forces resolvers to evaluate all algorithm combinations, consuming excessive CPU. It affects multiple DNS resolver implementations including BIND, Unbound, PowerDNS Recursor, Knot Resolver, dnsmasq, and Windows Server DNS. Because DNSSEC validation is widely deployed, a single crafted response can stall or take down a resolver, disrupting name resolution for all clients behind it.
Impact
An attacker can cause a denial of service by exhausting CPU on the validating resolver, making it unable to answer legitimate DNS queries. There is no confidentiality or integrity impact; the effect is availability loss for the resolver and its dependent services.
Attack surface
The flaw is reachable remotely over the network by sending one or more crafted DNSSEC responses to a validating resolver, as reflected in the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required; the attacker only needs to get the resolver to process a malicious response, for example by controlling or spoofing an authoritative zone.
Exploitation
CISA KEV does not list this CVE, but EPSS is extremely high at 0.99988 (99.984th percentile), indicating a strong likelihood of exploitation activity. References include vendor advisories and patches from Microsoft, ISC, NLnet Labs, PowerDNS, and Knot Resolver, but no public exploit code is tagged in the record.
What to do
- Apply vendor patches for all affected resolvers: BIND, Unbound 1.19.1+, PowerDNS Recursor, Knot Resolver 5.7.1+, dnsmasq, and Windows Server DNS updates from Microsoft.
- If immediate patching is not possible, reduce exposure by limiting DNSSEC validation to trusted zones or temporarily disabling validation where operationally acceptable.
- Restrict recursive resolver access to trusted clients and networks to reduce the pool of attackers who can send crafted responses.
- Monitor resolver CPU and query latency for anomalies and rate-limit or block sources generating excessive DNSSEC validation load.
- Track vendor advisories for updated guidance, as the underlying protocol issue may require further changes beyond initial patches.
Detection
- Monitor DNS resolver CPU utilization and query response latency for sustained spikes consistent with KeyTrap-style validation exhaustion.
- Log and alert on DNSSEC responses containing unusually large numbers of DNSKEY and RRSIG records or algorithm combinations.
- Baseline normal DNSSEC validation load per resolver and flag deviations, especially from a single source or zone.
- Review resolver logs for timeouts, SERVFAIL spikes, or dropped queries that correlate with high CPU periods.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-50387 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-50387), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.