To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade python3-bindUpgrade bind9.16-develUpgrade bind-dnssec-docUpgrade bind-chrootUpgrade python3-bind9.16Upgrade bind9.16Upgrade bind9.16-utilsUpgrade bind-libsUpgrade bind-utilsUpgrade bind-develUpgrade bind-licenseUpgrade bind9.16-libsUpgrade bind9.16-chrootUpgrade bindUpgrade bind-docUpgrade bind9.16-licenseUpgrade bind-dyndb-ldapUpgrade bind-dnssec-utilsUpgrade bind9.16-docUpgrade bind9.16-dnssec-utils | Apr 15, 2024 | Feb 13, 2024 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Feb 13, 2024 |
| Amazon_linux_2023 | — | Upgrade bind-dnssec-utils-debuginfoUpgrade bind-dlz-ldapUpgrade bind-dlz-mysql-debuginfoUpgrade bind-dlz-ldap-debuginfoUpgrade bind-develUpgrade bind-licenseUpgrade bind-libs-debuginfoUpgrade bind-dlz-mysqlUpgrade bind-pkcs11-develUpgrade python3-bindUpgrade bind-dlz-sqlite3-debuginfoUpgrade bind-dnssec-utilsUpgrade bind-dlz-sqlite3Upgrade bind-utilsUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-debugsourceUpgrade bind-utils-debuginfoUpgrade bind-dnssec-docUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-dlz-filesystemUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-libsUpgrade bind-dlz-filesystem-debuginfoUpgrade bindUpgrade bind-pkcs11Upgrade bind-docUpgrade bind-debuginfoUpgrade bind-chroot | Feb 17, 2025 | Feb 13, 2024 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Feb 13, 2024 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Dell Powerstore Dsa2025050 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jan 28, 2025 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Feb 15, 2024 | Feb 15, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade bind-pkcs11-utilsUpgrade bind-dnssec-utilsUpgrade bindUpgrade bind-licenseUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade python3-bindUpgrade bind-pkcs11Upgrade bind-libsUpgrade bind-chrootUpgrade bind-dnssec-doc | Jun 3, 2024 | Feb 13, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade bind-pkcs11Upgrade bind-dnssec-utilsUpgrade bind-licenseUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-libsUpgrade bind-chrootUpgrade python3-bindUpgrade bind-dnssec-docUpgrade bind-pkcs11-libsUpgrade bind-utils | May 31, 2024 | Feb 13, 2024 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory26 | Jun 5, 2024 | Feb 13, 2024 |
| Oracle_linux | — | Upgrade bind9.16Upgrade bind9.16-utilsUpgrade bind9.16-dnssec-utilsUpgrade python3-bind9.16Upgrade python3-bindUpgrade bind9.16-licenseUpgrade bind-dyndb-ldapUpgrade bindUpgrade bind-develUpgrade bind-libsUpgrade bind9.16-chrootUpgrade bind-licenseUpgrade bind-dnssec-docUpgrade bind-utilsUpgrade bind-dnssec-utilsUpgrade bind9.16-libsUpgrade bind-docUpgrade bind-chrootUpgrade bind9.16-develUpgrade bind9.16-doc | Apr 12, 2024 | Feb 13, 2024 |
| Redhat_linux | — | Upgrade bind9.16-libsUpgrade bind-utils-debuginfoUpgrade bind-dnssec-utilsUpgrade bind-chrootUpgrade bind-debugsourceUpgrade bind9.16-docUpgrade bind9.16-develUpgrade bind-docUpgrade bind-utilsUpgrade bind-dnssec-docUpgrade bind-dnssec-utils-debuginfoUpgrade bind-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade bind9.16-debuginfoUpgrade bind9.16-dnssec-utilsUpgrade bind-licenseUpgrade bind-libsUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-debugsourceUpgrade bind9.16-libs-debuginfoUpgrade python3-bindUpgrade python3-bind9.16Upgrade bind9.16-licenseUpgrade bind9.16-utilsUpgrade bind-dyndb-ldap-debuginfoUpgrade bind9.16-chrootUpgrade bind-dyndb-ldapUpgrade bind-develUpgrade bind9.16-utils-debuginfoUpgrade bind9.16Upgrade bindUpgrade bind-libs-debuginfo | Apr 3, 2024 | Feb 13, 2024 |
| Rocky_linux | — | Upgrade bind9.16Upgrade bind9.16-libsUpgrade bind-debugsourceUpgrade bind9.16-libs-debuginfoUpgrade bind-utilsUpgrade bindUpgrade bind-debuginfoUpgrade bind-dnssec-utilsUpgrade bind9.16-develUpgrade bind-chrootUpgrade bind-develUpgrade bind-dyndb-ldap-debuginfoUpgrade bind-utils-debuginfoUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-debugsourceUpgrade bind-dnssec-utils-debuginfoUpgrade bind9.16-utilsUpgrade bind-libsUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-chrootUpgrade bind-dyndb-ldapUpgrade bind-libs-debuginfo | May 8, 2024 | Feb 13, 2024 |
| Suse | — | Upgrade libisccfg1600Upgrade libns1604Upgrade libirs1601Upgrade libisccc1600Upgrade python3-bindUpgrade libuv1Upgrade bind-develUpgrade bind-chrootenvUpgrade libdns1605Upgrade libuv-develUpgrade libisc1606Upgrade libbind9-1600Upgrade libirs-develUpgrade bind-utilsUpgrade bindUpgrade bind-doc | Feb 22, 2024 | Feb 13, 2024 |
| Ubuntu | — | Upgrade bind9 | Feb 21, 2024 | Feb 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub