If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.0 Base Score: 3.7
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Jan 16, 2019 | Jan 16, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 16, 2019 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 15, 2017 | Jun 15, 2017 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Oct 30, 2017 | Aug 17, 2017 |
| Hpux | — | Update NameService to the latest version | Nov 9, 2017 | Oct 7, 2017 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Oct 19, 2018 |
| Suse | — | Upgrade bind-utilsUpgrade bindUpgrade libisccc160Upgrade libirs-develUpgrade bind-chrootenvUpgrade bind-develUpgrade python3-bindUpgrade libirs160Upgrade libisccfg1600Upgrade libdns169Upgrade libisc1606Upgrade bind-docUpgrade liblwres160Upgrade libns1604Upgrade libbind9-160Upgrade libisccc1600Upgrade libisccfg160Upgrade libbind9-1600Upgrade libirs1601Upgrade libdns1605Upgrade libisc166 | May 20, 2018 | May 20, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub