In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade bind-sdbUpgrade bind-utilsUpgrade bind-libsUpgrade bind-pkcs11Upgrade bind-lite-develUpgrade bind-pkcs11-libsUpgrade python3-bindUpgrade bind-chrootUpgrade bind-pkcs11-develUpgrade bind-sdb-chrootUpgrade bind-export-libsUpgrade bind-libs-liteUpgrade bind-licenseUpgrade bind-develUpgrade bind-export-develUpgrade bindUpgrade bind-pkcs11-utils | May 13, 2022 | Oct 27, 2021 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Oct 27, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 27, 2021 |
| Centos_linux | — | Upgrade bind-sdb-chrootUpgrade bind-pkcs11-libsUpgrade bind-debuginfoUpgrade bind-develUpgrade bind-pkcs11Upgrade python3-bindUpgrade bind-chrootUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-libs-debuginfoUpgrade bind-libsUpgrade bind-export-libs-debuginfoUpgrade bind-sdb-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11-develUpgrade bind-utilsUpgrade bind-debugsourceUpgrade bind-libs-lite-debuginfoUpgrade bind-sdbUpgrade bind-pkcs11-debuginfoUpgrade bind-export-libsUpgrade bind-pkcs11-utils-debuginfoUpgrade bindUpgrade bind-export-develUpgrade bind-licenseUpgrade bind-utils-debuginfoUpgrade bind-lite-devel | May 13, 2022 | Oct 27, 2021 |
| Debian | — | Upgrade bind9 | Nov 29, 2021 | Oct 27, 2021 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 1, 2022 | Oct 27, 2021 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 8, 2021 |
| Gentoo Linux | — | Upgrade net-dns/bind.Upgrade net-dns/bind-tools. | Oct 31, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp10 | — | Upgrade dhcp | Feb 28, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp11 | — | Upgrade dhcp | Jan 6, 2023 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-libsUpgrade bind-pkcs11 | May 25, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bind-pkcs11-libsUpgrade bind-libsUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-pkcs11 | Mar 2, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade dhcp | Jan 28, 2022 | Oct 27, 2021 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory20 | Oct 12, 2022 | Oct 27, 2021 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.11.36.0.0-11.4.40.0.1.107.3 on Solaris 11.4Upgrade service/network/dns/bind to version 9.11.36.0.0-11.4.40.0.1.107.3 on Solaris 11.4 | Dec 13, 2021 | Oct 27, 2021 |
| Oracle_linux | — | Upgrade python3-bindUpgrade bind-develUpgrade bind-pkcs11-utilsUpgrade bind-lite-develUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-pkcs11Upgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-libs-liteUpgrade bindUpgrade bind-export-libsUpgrade bind-pkcs11-develUpgrade bind-export-develUpgrade bind-sdbUpgrade bind-licenseUpgrade bind-sdb-chroot | May 18, 2022 | Oct 27, 2021 |
| Redhat_linux | — | Upgrade bind-sdbUpgrade bind-utils-debuginfoUpgrade bind-lite-develUpgrade bind-libsUpgrade bind-libs-lite-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bindUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bind-debugsourceUpgrade bind-pkcs11Upgrade bind-export-libsUpgrade bind-sdb-chrootUpgrade bind-develUpgrade bind-pkcs11-utilsUpgrade python3-bindUpgrade bind-debuginfoUpgrade bind-export-develUpgrade bind-libs-debuginfoUpgrade bind-sdb-debuginfoUpgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bind-utilsNo solution existsUpgrade bind-export-libs-debuginfoUpgrade bind-libs-lite | May 13, 2022 | Oct 27, 2021 |
| Rocky_linux | — | Upgrade bind-utils-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bind-develUpgrade bind-sdbUpgrade bind-pkcs11-utilsUpgrade bind-debuginfoUpgrade bind-debugsourceUpgrade bind-export-libs-debuginfoUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-export-develUpgrade bindUpgrade bind-lite-develUpgrade bind-export-libsUpgrade bind-libsUpgrade bind-pkcs11Upgrade bind-pkcs11-develUpgrade bind-sdb-debuginfoUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-debuginfoUpgrade bind-sdb-chrootUpgrade bind-libs-debuginfoUpgrade bind-pkcs11-utils-debuginfo | Mar 5, 2024 | Oct 27, 2021 |
| Suse | — | Upgrade libisc1606-32bitUpgrade bind-devel-32bitUpgrade bind-chrootenvUpgrade libbind9-1600Upgrade libisc1606Upgrade bind-develUpgrade liblwres161Upgrade python3-bindUpgrade libisccc1600Upgrade libirs1601Upgrade libbind9-161Upgrade libdns1605Upgrade libisccc1600-32bitUpgrade libisccfg1600Upgrade libns1604Upgrade bind-utilsUpgrade libisc1107Upgrade libbind9-1600-32bitUpgrade libisccfg163Upgrade libdns1605-32bitUpgrade bindUpgrade libns1604-32bitUpgrade libirs161Upgrade libisccc161Upgrade bind-docUpgrade libirs1601-32bitUpgrade libisc1107-32bitUpgrade libdns1110Upgrade libirs-develUpgrade python-bindUpgrade libisccfg1600-32bit | Nov 12, 2021 | Oct 27, 2021 |
| Ubuntu | — | Upgrade bind9Upgrade bind9 (Ubuntu Pro) | Oct 29, 2021 | Oct 27, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 27, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub