In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | Aug 22, 2024 | Aug 21, 2020 |
| Amazon Linux Ami 2 | — | Upgrade bind-licenseUpgrade bind-pkcs11-libsUpgrade bind-sdb-chrootUpgrade bind-pkcs11Upgrade bind-libs-liteUpgrade bind-pkcs11-utilsUpgrade bind-develUpgrade bind-pkcs11-develUpgrade bind-libsUpgrade bind-lite-develUpgrade bind-export-libsUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-sdbUpgrade bind-export-develUpgrade bind | Dec 10, 2020 | Aug 21, 2020 |
| Amazon_linux | — | Upgrade bind | Dec 19, 2020 | Aug 21, 2020 |
| Centos_linux | — | Upgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-libs-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-export-libsUpgrade bind-pkcs11-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-debugsourceUpgrade bind-sdbUpgrade bind-export-develUpgrade bind-pkcs11-libsUpgrade bind-debuginfoUpgrade bind-export-libs-debuginfoUpgrade bind-develUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-libs-lite-debuginfoUpgrade python3-bindUpgrade bind-chrootUpgrade bind-lite-develUpgrade bind-sdb-chrootUpgrade bind-libsUpgrade bind-sdb-debuginfoUpgrade bind-utilsUpgrade bindUpgrade bind-pkcs11 | Oct 9, 2020 | Aug 21, 2020 |
| Debian | — | Upgrade bind9 | Aug 31, 2020 | Aug 21, 2020 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Sep 8, 2020 | Aug 21, 2020 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 27, 2020 |
| Gentoo Linux | — | Upgrade net-dns/bind. | Aug 31, 2020 | Aug 21, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade bind-licenseUpgrade bind-pkcs11-libsUpgrade bind-libs-liteUpgrade bind-chrootUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-pkcs11Upgrade bind-libsUpgrade bind-utils | Nov 3, 2020 | Aug 21, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bind-utilsUpgrade bindUpgrade bind-pkcs11-utilsUpgrade bind-chrootUpgrade bind-libs-liteUpgrade bind-pkcs11-libsUpgrade bind-licenseUpgrade bind-libsUpgrade bind-pkcs11 | Sep 28, 2020 | Aug 21, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bindUpgrade bind-libsUpgrade bind-chrootUpgrade bind-licenseUpgrade bind-pkcs11Upgrade bind-pkcs11-utilsUpgrade bind-libs-lite | Nov 2, 2020 | Aug 21, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade bind-pkcs11Upgrade python3-bindUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-licenseUpgrade bind-libsUpgrade bind-export-libsUpgrade bind-libs-liteUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-export-develUpgrade bind-chroot | Aug 31, 2020 | Aug 21, 2020 |
| Huawei Euleros 2_0_sp9 | — | Upgrade python3-bindUpgrade bind-chrootUpgrade bind-libs-liteUpgrade bind-utilsUpgrade bind-export-libsUpgrade bind-pkcs11Upgrade bind-libsUpgrade bind | Oct 13, 2020 | Aug 21, 2020 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory18 | Dec 21, 2020 | Aug 21, 2020 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 19, 2022 |
| Oracle Solaris | — | Upgrade network/dns/bind to version 9.11.22.0.0-11.4.26.0.1.75.1 on Solaris 11.4Upgrade service/network/dns/bind to version 9.11.22.0.0-11.4.26.0.1.75.1 on Solaris 11.4 | Jan 19, 2021 | Aug 21, 2020 |
| Oracle_linux | — | Upgrade bind-sdb-chrootUpgrade bind-export-libsUpgrade bind-libs-liteUpgrade python3-bindUpgrade bind-utilsUpgrade bind-lite-develUpgrade bind-pkcs11-utilsUpgrade bind-chrootUpgrade bind-pkcs11-libsUpgrade bind-libsUpgrade bind-develUpgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bindUpgrade bind-sdbUpgrade bind-pkcs11Upgrade bind-export-devel | Oct 9, 2020 | Aug 20, 2020 |
| Redhat_linux | — | Upgrade bind-libs-liteUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-export-libsUpgrade bind-sdb-debuginfoUpgrade bind-debugsourceUpgrade bind-sdbUpgrade bind-export-develUpgrade bind-sdb-chrootUpgrade bind-chrootUpgrade bind-utils-debuginfoNo solution existsUpgrade bind-utilsUpgrade bind-lite-develUpgrade python3-bindUpgrade bind-pkcs11-develUpgrade bind-develUpgrade bind-libs-debuginfoUpgrade bind-licenseUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-debuginfoUpgrade bind-export-libs-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11Upgrade bind | Oct 9, 2020 | Aug 21, 2020 |
| Suse | — | Upgrade libns1604Upgrade libbind9-161Upgrade liblwres161Upgrade python3-bindUpgrade bind-chrootenvUpgrade libbind9-1600-32bitUpgrade bind-develUpgrade libisccc1600Upgrade libuv-develUpgrade bind-libsUpgrade libisccfg1600Upgrade libisccfg163Upgrade libdns1605-32bitUpgrade sysuser-toolsUpgrade libuv1Upgrade libdns1605Upgrade libisc1606-32bitUpgrade libisc1107Upgrade bind-utilsUpgrade libirs1601Upgrade bind-docUpgrade libisccc161Upgrade libisccc1600-32bitUpgrade libns1604-32bitUpgrade libirs1601-32bitUpgrade libdns1110Upgrade libisc1107-32bitUpgrade libirs161Upgrade python-bindUpgrade sysuser-shadowUpgrade bindUpgrade libisc1606Upgrade libirs-develUpgrade bind-libs-32bitUpgrade libbind9-1600Upgrade libuv1-32bitUpgrade libisccfg1600-32bitUpgrade bind-devel-32bit | Oct 14, 2020 | Aug 21, 2020 |
| Ubuntu | — | Upgrade bind9 (Ubuntu Pro)Upgrade bind9 | Aug 22, 2020 | Aug 21, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub