An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | May 25, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade bindUpgrade bind-pkcs11Upgrade bind-develUpgrade bind-pkcs11-utilsUpgrade bind-sdbUpgrade bind-libs-liteUpgrade bind-export-develUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-utilsUpgrade bind-libsUpgrade bind-lite-develUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-develUpgrade bind-sdb-chrootUpgrade bind-export-libsUpgrade bind-license | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade bind-debuginfoUpgrade bindUpgrade bind-licenseUpgrade bind-docUpgrade bind-debugsourceUpgrade bind-utils-debuginfoUpgrade bind-dnssec-utilsUpgrade bind-dnssec-utils-debuginfoUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-libs-debuginfoUpgrade bind-develUpgrade bind-libs | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade bind9 | May 24, 2026 | May 24, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Aug 13, 2026 | Aug 12, 2026 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory30 | Jun 29, 2026 | Jun 29, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 26, 2026 |
| Ubuntu | — | Upgrade bind9 | May 25, 2026 | May 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub