An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jan 13, 2017 | Jan 13, 2017 |
| Freebsd | — | Upgrade bind911Upgrade bind910Upgrade bind9-develUpgrade bind99Upgrade FreeBSD | Jan 12, 2017 | Jan 12, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade bind-utilsUpgrade libdns1605Upgrade libisccfg160Upgrade libisccc1600Upgrade libirs1601Upgrade liblwres160Upgrade libns1604Upgrade libbind9-1600Upgrade libisc1606Upgrade libisccfg1600Upgrade python3-bindUpgrade libisccc160Upgrade bind-chrootenvUpgrade bindUpgrade bind-develUpgrade bind-docUpgrade libirs-develUpgrade libbind9-160Upgrade libisc166Upgrade libirs160Upgrade libdns169 | May 20, 2018 | Jan 11, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub