In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-licenseUpgrade bind-export-develUpgrade bind-export-libsUpgrade bind-libs-liteUpgrade bind-develUpgrade bind-sdb-chrootUpgrade bind-pkcs11-develUpgrade bind-libsUpgrade bind-chrootUpgrade python3-bindUpgrade bind-utilsUpgrade bind-sdbUpgrade bind-pkcs11-libsUpgrade bind-lite-develUpgrade bind-pkcs11 | May 13, 2022 | Oct 27, 2021 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Oct 27, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 27, 2021 |
| Centos_linux | — | Upgrade bind-libs-lite-debuginfoUpgrade bind-lite-develUpgrade bind-utils-debuginfoUpgrade bind-sdb-debuginfoUpgrade bind-licenseUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-export-libsUpgrade bind-sdbUpgrade bind-debugsourceUpgrade bind-export-develUpgrade bindUpgrade bind-utilsUpgrade bind-pkcs11-develUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11Upgrade bind-pkcs11-libsUpgrade bind-libs-debuginfoUpgrade python3-bindUpgrade bind-export-libs-debuginfoUpgrade bind-debuginfoUpgrade bind-develUpgrade bind-sdb-chrootUpgrade bind-chrootUpgrade bind-libs-liteUpgrade bind-pkcs11-utilsUpgrade bind-libs | May 13, 2022 | Oct 27, 2021 |
| Debian | — | Upgrade bind9 | Nov 29, 2021 | Oct 27, 2021 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Jun 1, 2022 | Oct 27, 2021 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Nov 8, 2021 |
| Gentoo Linux | — | Upgrade net-dns/bind-tools.Upgrade net-dns/bind. | Oct 31, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp10 | — | Upgrade dhcp | Feb 28, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp11 | — | Upgrade dhcp | Jan 6, 2023 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade bind-chrootUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-utilsUpgrade bind-pkcs11Upgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-licenseUpgrade bind | May 25, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade bind-utilsUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-chrootUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-pkcs11Upgrade bindUpgrade bind-license | Mar 2, 2022 | Oct 27, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade dhcp | Jan 28, 2022 | Oct 27, 2021 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory20 | Oct 12, 2022 | Oct 27, 2021 |
| Oracle Solaris | — | Upgrade service/network/dns/bind to version 9.11.36.0.0-11.4.40.0.1.107.3 on Solaris 11.4Upgrade network/dns/bind to version 9.11.36.0.0-11.4.40.0.1.107.3 on Solaris 11.4 | Dec 13, 2021 | Oct 27, 2021 |
| Oracle_linux | — | Upgrade bind-lite-develUpgrade bind-pkcs11-libsUpgrade bind-chrootUpgrade bind-utilsUpgrade bind-pkcs11Upgrade bind-pkcs11-utilsUpgrade bind-develUpgrade bind-libsUpgrade python3-bindUpgrade bind-export-libsUpgrade bindUpgrade bind-licenseUpgrade bind-sdb-chrootUpgrade bind-libs-liteUpgrade bind-export-develUpgrade bind-sdbUpgrade bind-pkcs11-devel | May 18, 2022 | Oct 27, 2021 |
| Redhat_linux | — | Upgrade bind-sdb-chrootUpgrade bind-debuginfoUpgrade bind-export-develUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-develNo solution existsUpgrade bind-develUpgrade bind-utilsUpgrade bind-libs-liteUpgrade bind-licenseUpgrade bind-libs-debuginfoUpgrade python3-bindUpgrade bind-sdb-debuginfoUpgrade bind-export-libsUpgrade bind-export-libs-debuginfoUpgrade bind-pkcs11Upgrade bind-pkcs11-libs-debuginfoUpgrade bind-debugsourceUpgrade bind-utils-debuginfoUpgrade bind-sdbUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-libs-lite-debuginfoUpgrade bindUpgrade bind-pkcs11-libsUpgrade bind-chrootUpgrade bind-lite-develUpgrade bind-pkcs11-debuginfoUpgrade bind-libs | May 13, 2022 | Oct 27, 2021 |
| Rocky_linux | — | Upgrade bind-libs-lite-debuginfoUpgrade bind-libsUpgrade bind-export-libsUpgrade bind-export-develUpgrade bind-pkcs11-utilsUpgrade bind-debugsourceUpgrade bind-libs-liteUpgrade bind-lite-develUpgrade bindUpgrade bind-chrootUpgrade bind-develUpgrade bind-utils-debuginfoUpgrade bind-sdbUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-debuginfoUpgrade bind-utilsUpgrade bind-export-libs-debuginfoUpgrade bind-pkcs11Upgrade bind-pkcs11-utils-debuginfoUpgrade bind-pkcs11-develUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-debuginfoUpgrade bind-libs-debuginfoUpgrade bind-sdb-debuginfoUpgrade bind-sdb-chroot | Mar 5, 2024 | Oct 27, 2021 |
| Suse | — | Upgrade bind-utilsUpgrade libirs1601Upgrade libdns1605-32bitUpgrade bind-devel-32bitUpgrade libisccfg1600Upgrade liblwres161Upgrade libisc1606-32bitUpgrade libisc1606Upgrade libbind9-161Upgrade libbind9-1600Upgrade libisccc1600-32bitUpgrade libbind9-1600-32bitUpgrade libisccfg163Upgrade python3-bindUpgrade libdns1605Upgrade bind-chrootenvUpgrade libisc1107Upgrade bind-develUpgrade libns1604Upgrade libisccc1600Upgrade libirs-develUpgrade libns1604-32bitUpgrade python-bindUpgrade libirs1601-32bitUpgrade libdns1110Upgrade libisc1107-32bitUpgrade libisccc161Upgrade libirs161Upgrade bindUpgrade libisccfg1600-32bitUpgrade bind-doc | Nov 12, 2021 | Oct 27, 2021 |
| Ubuntu | — | Upgrade bind9Upgrade bind9 (Ubuntu Pro) | Oct 29, 2021 | Oct 27, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 27, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub