ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade bind-develUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-sdbUpgrade bind-libsUpgrade bind | Dec 1, 2016 | Jan 25, 2013 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 25, 2013 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jan 31, 2013 | Jan 25, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 29, 2014 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 25, 2013 |
| Oracle_linux | — | Upgrade bind-utilsUpgrade bind-chrootUpgrade bind-libsUpgrade bindUpgrade bind-develUpgrade bind-sdb | Oct 16, 2024 | Jan 25, 2013 |
| Suse | — | Upgrade bind-docUpgrade bind-modules-ldapUpgrade libbind9-160Upgrade libisccfg160Upgrade libisccc160Upgrade liblwres160Upgrade libdns169Upgrade bind-modules-sqlite3Upgrade bindUpgrade bind-modules-mysqlUpgrade bind-libsUpgrade libirs-develUpgrade libisc166Upgrade bind-develUpgrade python-bindUpgrade bind-utilsUpgrade bind-modules-genericUpgrade libirs160Upgrade bind-libs-32bitUpgrade bind-chrootenvUpgrade bind-modules-perlUpgrade libisc166-32bitUpgrade python3-bind | Aug 9, 2024 | Jul 9, 2013 |
| Ubuntu | — | Upgrade bind9 | Nov 8, 2024 | Jan 25, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub