A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.0 -> 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0 -> 9.11.0-P3, 9.11.1b1->9.11.1rc1, 9.9.3-S1 -> 9.9.9-S8.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jan 16, 2019 | Jan 16, 2019 |
| Amazon_linux | — | Upgrade bind | May 2, 2017 | Apr 12, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Centos_linux | — | Upgrade bind-lite-develUpgrade bind-debuginfoUpgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bind-sdbUpgrade bind-develUpgrade bind-utilsUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-pkcs11Upgrade bind-sdb-chrootUpgrade bind-libsUpgrade bind-licenseUpgrade bindUpgrade bind-pkcs11-devel | Apr 20, 2017 | Apr 12, 2017 |
| Debian | — | Upgrade bind9 | May 15, 2017 | Apr 12, 2017 |
| Dns Bind | — | Upgrade ISC BIND to latest version | May 15, 2017 | May 15, 2017 |
| Freebsd | — | Upgrade bind910Upgrade bind911Upgrade bind99Upgrade bind9-devel | Apr 13, 2017 | Apr 13, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Hpux | — | Update NameService.BIND-RUN to the latest versionUpdate NameService.BIND-AUX to the latest version | Aug 11, 2017 | Jun 30, 2017 |
| Huawei Euleros 2_0_sp1 | — | Upgrade bind-libs-liteUpgrade bind-libsUpgrade bind-chrootUpgrade bind-utilsUpgrade bindUpgrade bind-license | Oct 4, 2019 | Jan 16, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bindUpgrade bind-pkcs11Upgrade bind-pkcs11-utilsUpgrade bind-licenseUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-libs | Oct 4, 2019 | Jan 16, 2019 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 19, 2018 |
| Oracle_linux | — | Upgrade bind-sdb-chrootUpgrade bind-libsUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-develUpgrade bind-sdbUpgrade bind-lite-develUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-pkcs11Upgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-develUpgrade bind-license | Apr 19, 2017 | Apr 12, 2017 |
| Redhat_linux | — | Upgrade bind-pkcs11-develUpgrade bind-pkcs11-libsUpgrade bind-licenseUpgrade bind-pkcs11Upgrade bind-sdb-chrootUpgrade bind-libs-liteUpgrade bind-libsUpgrade bind-utilsUpgrade bind-develUpgrade bind-sdbUpgrade bind-pkcs11-utilsUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-lite-develUpgrade bind | Apr 19, 2017 | Apr 12, 2017 |
| Suse | — | Upgrade libbind9-1600-32bitUpgrade libisccc160Upgrade python-bindUpgrade liblwres160Upgrade libns1604Upgrade libisccfg160Upgrade libirs1601Upgrade libisc166-32bitUpgrade libirs1601-32bitUpgrade libisc1606Upgrade libuv1-32bitUpgrade bind-libs-x86Upgrade python3-bindUpgrade libbind9-160Upgrade libdns1605Upgrade libisc1606-32bitUpgrade libbind9-1600Upgrade libdns1605-32bitUpgrade sysuser-shadowUpgrade libdns169Upgrade libuv1Upgrade libisccc1600Upgrade libuv-develUpgrade bind-docUpgrade bind-libs-32bitUpgrade bind-devel-32bitUpgrade sysuser-toolsUpgrade bindUpgrade bind-utilsUpgrade libisccfg1600-32bitUpgrade libirs160Upgrade libns1604-32bitUpgrade bind-libsUpgrade libirs-develUpgrade libisc166Upgrade libisccc1600-32bitUpgrade libisccfg1600Upgrade bind-chrootenvUpgrade bind-devel | Apr 13, 2017 | Apr 12, 2017 |
| Ubuntu | — | Upgrade bind9 | Apr 17, 2017 | Apr 12, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub