Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure.
'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade bind-dlz-sqlite3-debuginfoUpgrade bind-dlz-filesystemUpgrade bind-dlz-mysql-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-dlz-sqlite3Upgrade bind-dlz-filesystem-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-licenseUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-dnssec-docUpgrade bind-dlz-ldap-debuginfoUpgrade bindUpgrade bind-dnssec-utilsUpgrade bind-debugsourceUpgrade bind-dlz-ldapUpgrade bind-develUpgrade bind-libsUpgrade bind-dlz-mysqlUpgrade bind-pkcs11Upgrade bind-pkcs11-libsUpgrade bind-pkcs11-develUpgrade bind-libs-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-utilsUpgrade python3-bindUpgrade bind-debuginfo | Feb 17, 2025 | Jan 25, 2023 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Mar 7, 2023 | Jan 26, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub