buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 6.1.9 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 7.1.3 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 7.1.4 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 7.2.0 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Sep 28, 2016 |
| Amazon_linux | — | Upgrade bind | Sep 28, 2016 | Sep 28, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 28, 2016 |
| Centos_linux | — | Upgrade bind97-develUpgrade bind97-utilsUpgrade bind-pkcs11-develUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-licenseUpgrade bind97-libsUpgrade bind97-chrootUpgrade bind-sdb-chrootUpgrade bind97Upgrade bind-sdbUpgrade bind-lite-develUpgrade bind-chrootUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-develUpgrade bindUpgrade bind-pkcs11Upgrade bind-libs | Oct 21, 2016 | Sep 28, 2016 |
| Debian | — | Upgrade bind9 | Sep 28, 2016 | Sep 27, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Oct 12, 2016 | Sep 28, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 27, 2016 |
| Freebsd | — | Upgrade bind9-develUpgrade FreeBSDUpgrade bind911Upgrade bind99Upgrade bind910 | Nov 14, 2016 | Sep 28, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Sep 28, 2016 |
| Hpux | — | Update NameService.BIND-RUN to the latest versionUpdate NameService.BIND-AUX to the latest version | Aug 11, 2017 | Sep 28, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bindUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-libsUpgrade bind-libs-liteUpgrade bind-license | Nov 30, 2017 | Sep 28, 2016 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory13 | Nov 30, 2017 | Sep 28, 2016 |
| Oracle Solaris | — | Upgrade service/network/dns/bind to version 9.6.3.11.8-0.175.3.14.0.2.0 on Solaris 11.3Upgrade network/dns/bind to version 9.6.3.11.8-0.175.3.14.0.2.0 on Solaris 11.3 | May 29, 2017 | Sep 28, 2016 |
| Oracle_linux | — | Upgrade bind-utilsUpgrade bind-libsUpgrade bind-pkcs11-utilsUpgrade bind97-chrootUpgrade bind-develUpgrade bind-chrootUpgrade bind-sdbUpgrade bind-sdb-chrootUpgrade bind-pkcs11Upgrade bindUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind97Upgrade bind-libbind-develUpgrade bind97-libsUpgrade bind-pkcs11-develUpgrade bind-licenseUpgrade bind-pkcs11-libsUpgrade bind97-utilsUpgrade caching-nameserverUpgrade bind97-devel | Sep 28, 2016 | Sep 27, 2016 |
| Redhat_linux | — | Upgrade bind-chrootUpgrade bind-sdb-chrootUpgrade bind97-debuginfoUpgrade bind-utilsUpgrade caching-nameserverUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-develUpgrade bind97-utilsUpgrade bind-pkcs11-utilsUpgrade bind-debuginfoNo solution existsUpgrade bind97-chrootUpgrade bind97-develUpgrade bind-libsUpgrade bind97-libsUpgrade bind-libbind-develUpgrade bind-pkcs11-libsUpgrade bind97Upgrade bindUpgrade bind-pkcs11-develUpgrade bind-licenseUpgrade bind-sdbUpgrade bind-pkcs11 | Oct 21, 2016 | Sep 28, 2016 |
| Suse | — | Upgrade bind-develUpgrade libisc166-32bitUpgrade libirs160Upgrade libisccc1600Upgrade bind-utilsUpgrade python-bindUpgrade bind-devel-32bitUpgrade libisccc160Upgrade libirs1601Upgrade bind-chrootenvUpgrade libirs-develUpgrade bind-libs-32bitUpgrade libisccfg1600Upgrade python3-bindUpgrade bind-libs-x86Upgrade libbind9-1600Upgrade bind-libsUpgrade libisc166Upgrade liblwres160Upgrade libbind9-160Upgrade libisccfg160Upgrade libns1604Upgrade libdns1605Upgrade bindUpgrade libdns169Upgrade bind-docUpgrade libisc1606 | Oct 12, 2016 | Sep 27, 2016 |
| Ubuntu | — | Upgrade bind9 | Sep 27, 2016 | Sep 27, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub