buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Aix 5.3.12 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 6.1.9 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 7.1.3 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 7.1.4 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Aix 7.2.0 Bind_advisory13 | — | — | Dec 19, 2016 | Sep 28, 2016 |
| Alpine Linux | — | Upgrade bind | Aug 30, 2017 | Sep 28, 2016 |
| Amazon_linux | — | Upgrade bind | Sep 28, 2016 | Sep 28, 2016 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 28, 2016 |
| Centos_linux | — | Upgrade bind-pkcs11-develUpgrade bind-utilsUpgrade bind97-utilsUpgrade bind-pkcs11-libsUpgrade bind97-chrootUpgrade bind97-libsUpgrade bind97-develUpgrade bind-sdb-chrootUpgrade bind-licenseUpgrade bind97Upgrade bind-chrootUpgrade bind-pkcs11-utilsUpgrade bind-libsUpgrade bind-sdbUpgrade bind-lite-develUpgrade bind-pkcs11Upgrade bindUpgrade bind-libs-liteUpgrade bind-devel | Oct 21, 2016 | Sep 28, 2016 |
| Debian | — | Upgrade bind9 | Sep 28, 2016 | Sep 27, 2016 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Oct 12, 2016 | Sep 28, 2016 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 27, 2016 |
| Freebsd | — | Upgrade FreeBSDUpgrade bind9-develUpgrade bind911Upgrade bind99Upgrade bind910 | Nov 14, 2016 | Sep 28, 2016 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Sep 28, 2016 |
| Hpux | — | Update NameService.BIND-RUN to the latest versionUpdate NameService.BIND-AUX to the latest version | Aug 11, 2017 | Sep 28, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bind-libs-liteUpgrade bind-licenseUpgrade bind-libsUpgrade bind-utilsUpgrade bindUpgrade bind-chroot | Nov 30, 2017 | Sep 28, 2016 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory13 | Nov 30, 2017 | Sep 28, 2016 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.6.3.11.8-0.175.3.14.0.2.0 on Solaris 11.3Upgrade service/network/dns/bind to version 9.6.3.11.8-0.175.3.14.0.2.0 on Solaris 11.3 | May 29, 2017 | Sep 28, 2016 |
| Oracle_linux | — | Upgrade bind97-utilsUpgrade caching-nameserverUpgrade bind97-libsUpgrade bind-pkcs11-develUpgrade bind97-develUpgrade bind-libbind-develUpgrade bind-pkcs11-libsUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bind-sdbUpgrade bind-pkcs11Upgrade bind-utilsUpgrade bind97-chrootUpgrade bind-develUpgrade bind-chrootUpgrade bindUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-libsUpgrade bind-sdb-chrootUpgrade bind97 | Sep 28, 2016 | Sep 27, 2016 |
| Redhat_linux | — | Upgrade bind-develUpgrade bind97-chrootNo solution existsUpgrade bind-pkcs11-utilsUpgrade bind-utilsUpgrade bind97-utilsUpgrade caching-nameserverUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind97-debuginfoUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bind-sdb-chrootUpgrade bind-sdbUpgrade bind97-libsUpgrade bindUpgrade bind-libbind-develUpgrade bind-pkcs11-libsUpgrade bind97-develUpgrade bind-libsUpgrade bind97Upgrade bind-pkcs11-develUpgrade bind-pkcs11Upgrade bind-license | Oct 21, 2016 | Sep 28, 2016 |
| Suse | — | Upgrade libisccc160Upgrade python-bindUpgrade libisccc1600Upgrade bind-devel-32bitUpgrade libisc166-32bitUpgrade bind-chrootenvUpgrade libisccfg1600Upgrade bind-develUpgrade libirs-develUpgrade bind-libs-32bitUpgrade bind-utilsUpgrade libirs1601Upgrade libirs160Upgrade python3-bindUpgrade bind-libs-x86Upgrade libbind9-1600Upgrade liblwres160Upgrade bind-docUpgrade libdns1605Upgrade libns1604Upgrade libbind9-160Upgrade libisc1606Upgrade bind-libsUpgrade libisc166Upgrade libisccfg160Upgrade bindUpgrade libdns169 | Oct 12, 2016 | Sep 27, 2016 |
| Ubuntu | — | Upgrade bind9 | Sep 27, 2016 | Sep 27, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub