In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-bindUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-lite-develUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11Upgrade bind-sdbUpgrade bind-export-develUpgrade bind-libs-liteUpgrade bindUpgrade bind-develUpgrade bind-sdb-chrootUpgrade bind-export-libsUpgrade bind-pkcs11-utilsUpgrade bind-licenseUpgrade bind-pkcs11-devel | May 13, 2022 | Oct 27, 2021 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Oct 27, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 27, 2021 |
| Centos_linux | — | Upgrade bind-sdb-chrootUpgrade bind-libsUpgrade bind-libs-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11Upgrade bind-pkcs11-libsUpgrade python3-bindUpgrade bind-chrootUpgrade bind-debuginfoUpgrade bind-develUpgrade bind-export-libs-debuginfoUpgrade bind-libs-liteUpgrade bind-libs-lite-debuginfoUpgrade bind-debugsourceUpgrade bind-utilsUpgrade bind-lite-develUpgrade bind-licenseUpgrade bind-sdb-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-export-develUpgrade bind-export-libsUpgrade bindUpgrade bind-sdbUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-develUpgrade bind-utils-debuginfo | May 13, 2022 | Oct 27, 2021 |
| Debian | — | Upgrade bind9 | Nov 29, 2021 | Oct 27, 2021 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 1, 2022 | Oct 27, 2021 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 8, 2021 |
| Gentoo Linux | — | Upgrade net-dns/bind.Upgrade net-dns/bind-tools. | Oct 31, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp10 | — | Upgrade dhcp | Feb 28, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp11 | — | Upgrade dhcp | Jan 6, 2023 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bindUpgrade bind-licenseUpgrade bind-chrootUpgrade bind-libsUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11 | May 25, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bind-utilsUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-utilsUpgrade bind-chrootUpgrade bindUpgrade bind-libs-liteUpgrade bind-licenseUpgrade bind-pkcs11 | Mar 2, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade dhcp | Jan 28, 2022 | Oct 27, 2021 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory20 | Oct 12, 2022 | Oct 27, 2021 |
| Oracle Solaris | — | Upgrade service/network/dns/bind to version 9.11.36.0.0-11.4.40.0.1.107.3 on Solaris 11.4Upgrade network/dns/bind to version 9.11.36.0.0-11.4.40.0.1.107.3 on Solaris 11.4 | Dec 13, 2021 | Oct 27, 2021 |
| Oracle_linux | — | Upgrade bind-pkcs11-develUpgrade bind-export-develUpgrade bind-sdbUpgrade bind-licenseUpgrade bind-libs-liteUpgrade bind-export-libsUpgrade bind-sdb-chrootUpgrade bindUpgrade bind-chrootUpgrade bind-develUpgrade python3-bindUpgrade bind-utilsUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11Upgrade bind-lite-develUpgrade bind-pkcs11-libsUpgrade bind-libs | May 18, 2022 | Oct 27, 2021 |
| Redhat_linux | — | Upgrade bind-pkcs11-utils-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-libsUpgrade bind-debugsourceUpgrade bind-libsUpgrade bind-chrootUpgrade bind-lite-develUpgrade bind-sdbUpgrade bindUpgrade bind-debuginfoUpgrade bind-libs-liteUpgrade bind-pkcs11Upgrade bind-licenseUpgrade bind-pkcs11-develUpgrade bind-export-develUpgrade bind-develUpgrade bind-sdb-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-libs-debuginfoUpgrade bind-utilsUpgrade python3-bindUpgrade bind-sdb-chrootNo solution existsUpgrade bind-export-libs-debuginfoUpgrade bind-export-libs | May 13, 2022 | Oct 27, 2021 |
| Rocky_linux | — | Upgrade bind-chrootUpgrade bind-export-libsUpgrade bind-utilsUpgrade bind-export-develUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11Upgrade bind-export-libs-debuginfoUpgrade bind-develUpgrade bind-utils-debuginfoUpgrade bindUpgrade bind-debugsourceUpgrade bind-sdbUpgrade bind-lite-develUpgrade bind-libs-liteUpgrade bind-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-libsUpgrade bind-sdb-chrootUpgrade bind-pkcs11-develUpgrade bind-pkcs11-libsUpgrade bind-libs-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-sdb-debuginfo | Mar 5, 2024 | Oct 27, 2021 |
| Suse | — | Upgrade libisccfg1600-32bitUpgrade libirs161Upgrade libisccc161Upgrade libdns1110Upgrade bindUpgrade python-bindUpgrade libirs1601-32bitUpgrade libisc1107-32bitUpgrade libirs-develUpgrade libns1604-32bitUpgrade bind-docUpgrade libisccc1600Upgrade libdns1605-32bitUpgrade libisccc1600-32bitUpgrade libbind9-1600-32bitUpgrade libisc1606Upgrade libbind9-161Upgrade libdns1605Upgrade bind-utilsUpgrade bind-develUpgrade libns1604Upgrade bind-chrootenvUpgrade liblwres161Upgrade libisc1107Upgrade python3-bindUpgrade libirs1601Upgrade libisccfg163Upgrade libbind9-1600Upgrade bind-devel-32bitUpgrade libisccfg1600Upgrade libisc1606-32bit | Nov 12, 2021 | Oct 27, 2021 |
| Ubuntu | — | Upgrade bind9Upgrade bind9 (Ubuntu Pro) | Oct 29, 2021 | Oct 27, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 27, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub