ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade bind-develUpgrade bind-chrootUpgrade bind-utilsUpgrade bindUpgrade bind-libsUpgrade bind-sdb | Dec 1, 2016 | Jan 25, 2013 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Jan 25, 2013 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jan 31, 2013 | Jan 25, 2013 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Jul 29, 2014 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Jan 25, 2013 |
| Oracle_linux | — | Upgrade bind-develUpgrade bind-chrootUpgrade bind-libsUpgrade bindUpgrade bind-sdbUpgrade bind-utils | Oct 16, 2024 | Jan 25, 2013 |
| Suse | — | Upgrade libirs-develUpgrade libisccfg160Upgrade bind-libsUpgrade libdns169Upgrade libisccc160Upgrade bind-docUpgrade bindUpgrade libbind9-160Upgrade liblwres160Upgrade libirs160Upgrade bind-develUpgrade python3-bindUpgrade bind-libs-32bitUpgrade bind-chrootenvUpgrade libisc166Upgrade python-bindUpgrade libisc166-32bitUpgrade bind-utils | Aug 9, 2024 | Jan 25, 2013 |
| Ubuntu | — | Upgrade bind9 | Nov 8, 2024 | Jan 25, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub