Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure.
'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade bind-chrootUpgrade bind-dlz-mysql-debuginfoUpgrade bind-dlz-sqlite3-debuginfoUpgrade bind-dlz-filesystemUpgrade bind-utils-debuginfoUpgrade bind-dlz-sqlite3Upgrade bind-dlz-ldapUpgrade bind-dnssec-utils-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bindUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-dnssec-docUpgrade bind-dnssec-utilsUpgrade bind-debugsourceUpgrade bind-licenseUpgrade bind-dlz-filesystem-debuginfoUpgrade bind-dlz-ldap-debuginfoUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-libs-debuginfoUpgrade bind-pkcs11-develUpgrade bind-pkcs11-utilsUpgrade bind-libsUpgrade bind-dlz-mysqlUpgrade bind-pkcs11Upgrade bind-pkcs11-debuginfoUpgrade bind-debuginfoUpgrade python3-bindUpgrade bind-devel | Feb 17, 2025 | Jan 25, 2023 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Mar 7, 2023 | Jan 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub