An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker could cause it to accept a query that possessed the required attributes. Please note: This vulnerability affects the "nxdomain-redirect" feature, which is one of two methods of handling NXDOMAIN redirection, and is only available in certain versions of BIND. Redirection using zones of type "redirect" is not affected by this vulnerability. Affects BIND 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jan 13, 2017 | Jan 13, 2017 |
| Freebsd | — | Upgrade bind910Upgrade bind911Upgrade FreeBSDUpgrade bind99Upgrade bind9-devel | Jan 12, 2017 | Jan 12, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Suse | — | Upgrade libirs1601Upgrade libisc1606Upgrade libisccfg1600Upgrade libns1604Upgrade bind-utilsUpgrade libdns1605Upgrade libisccfg160Upgrade libisccc1600Upgrade libbind9-1600Upgrade libisccc160Upgrade python3-bindUpgrade liblwres160Upgrade bind-chrootenvUpgrade libbind9-160Upgrade libirs-develUpgrade libisc166Upgrade bindUpgrade bind-develUpgrade libirs160Upgrade libdns169Upgrade bind-doc | May 20, 2018 | Jan 11, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub