To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-bindUpgrade bind-dnssec-docUpgrade bind9.16-utilsUpgrade bind-chrootUpgrade python3-bind9.16Upgrade bind9.16-develUpgrade bind9.16Upgrade bind-utilsUpgrade bind-develUpgrade bind-libsUpgrade bind-dnssec-utilsUpgrade bind-dyndb-ldapUpgrade bindUpgrade bind-licenseUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-licenseUpgrade bind9.16-libsUpgrade bind9.16-docUpgrade bind9.16-chrootUpgrade bind-doc | Apr 15, 2024 | Feb 13, 2024 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Feb 13, 2024 |
| Amazon_linux_2023 | — | Upgrade bind-debuginfoUpgrade bind-dnssec-docUpgrade bind-dlz-sqlite3Upgrade bindUpgrade bind-chrootUpgrade bind-pkcs11-debuginfoUpgrade bind-docUpgrade bind-utils-debuginfoUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11Upgrade bind-debugsourceUpgrade bind-dlz-filesystem-debuginfoUpgrade bind-libsUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-dlz-filesystemUpgrade bind-utilsUpgrade python3-bindUpgrade bind-licenseUpgrade bind-develUpgrade bind-dlz-ldap-debuginfoUpgrade bind-pkcs11-develUpgrade bind-dlz-mysqlUpgrade bind-libs-debuginfoUpgrade bind-dlz-sqlite3-debuginfoUpgrade bind-dlz-mysql-debuginfoUpgrade bind-dlz-ldapUpgrade bind-dnssec-utils-debuginfoUpgrade bind-dnssec-utils | Feb 17, 2025 | Feb 13, 2024 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Feb 13, 2024 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Dell Powerstore Dsa2025050 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jan 28, 2025 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Feb 15, 2024 | Feb 15, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade bind-pkcs11-utilsUpgrade bind-dnssec-utilsUpgrade bindUpgrade bind-licenseUpgrade bind-pkcs11-libsUpgrade python3-bindUpgrade bind-pkcs11Upgrade bind-utilsUpgrade bind-chrootUpgrade bind-dnssec-docUpgrade bind-libs | Jun 3, 2024 | Feb 13, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade bind-chrootUpgrade bind-dnssec-docUpgrade bind-pkcs11-libsUpgrade python3-bindUpgrade bind-utilsUpgrade bindUpgrade bind-licenseUpgrade bind-dnssec-utilsUpgrade bind-libsUpgrade bind-pkcs11-utilsUpgrade bind-pkcs11 | May 31, 2024 | Feb 13, 2024 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory26 | Jun 5, 2024 | Feb 13, 2024 |
| Oracle_linux | — | Upgrade bind-docUpgrade bind9.16-docUpgrade bind-utilsUpgrade bind-dnssec-utilsUpgrade bind9.16-libsUpgrade bind-chrootUpgrade bind-dnssec-docUpgrade bind9.16-develUpgrade bind-develUpgrade bind-dyndb-ldapUpgrade bind-libsUpgrade python3-bind9.16Upgrade python3-bindUpgrade bind-licenseUpgrade bind9.16-chrootUpgrade bindUpgrade bind9.16Upgrade bind9.16-utilsUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-license | Apr 12, 2024 | Feb 13, 2024 |
| Redhat_linux | — | Upgrade bind9.16Upgrade bind-libs-debuginfoUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-utilsUpgrade bind9.16-debugsourceUpgrade bind-dnssec-utils-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade bind9.16-licenseUpgrade bind-dyndb-ldap-debuginfoUpgrade bind-dyndb-ldapUpgrade python3-bind9.16Upgrade bind-debuginfoUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-debuginfoUpgrade python3-bindUpgrade bind-licenseUpgrade bind9.16-utils-debuginfoUpgrade bindUpgrade bind9.16-libs-debuginfoUpgrade bind-libsUpgrade bind-develUpgrade bind9.16-chrootUpgrade bind9.16-develUpgrade bind9.16-docUpgrade bind-utils-debuginfoUpgrade bind-docUpgrade bind-debugsourceUpgrade bind-chrootUpgrade bind9.16-libsUpgrade bind-dnssec-utilsUpgrade bind-utilsUpgrade bind-dnssec-doc | Apr 3, 2024 | Feb 13, 2024 |
| Rocky_linux | — | Upgrade bind-dyndb-ldapUpgrade bind9.16-chrootUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-debuginfoUpgrade bind-libs-debuginfoUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-dnssec-utilsUpgrade bind-utils-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade bind-dnssec-utils-debuginfoUpgrade bind-dyndb-ldap-debuginfoUpgrade bind9.16-debugsourceUpgrade bind9.16-utilsUpgrade bind-libsUpgrade bind9.16-libsUpgrade bind9.16-libs-debuginfoUpgrade bind-debuginfoUpgrade bind9.16-develUpgrade bind-chrootUpgrade bind-debugsourceUpgrade bind-dnssec-utilsUpgrade bind9.16Upgrade bind-develUpgrade bind-utilsUpgrade bind | May 8, 2024 | Feb 13, 2024 |
| Suse | — | Upgrade libisc1606Upgrade bind-develUpgrade libisccfg1600Upgrade libuv1Upgrade libdns1605Upgrade libirs-develUpgrade libns1604Upgrade python3-bindUpgrade libuv-develUpgrade libbind9-1600Upgrade libirs1601Upgrade libisccc1600Upgrade bind-chrootenvUpgrade bindUpgrade bind-docUpgrade bind-utils | Feb 22, 2024 | Feb 13, 2024 |
| Ubuntu | — | Upgrade bind9 | Feb 21, 2024 | Feb 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub