To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade bind-docUpgrade bind9.16-libsUpgrade bind-dyndb-ldapUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-licenseUpgrade bind-dnssec-utilsUpgrade bind9.16-docUpgrade bindUpgrade bind9.16-chrootUpgrade bind-licenseUpgrade bind-utilsUpgrade bind-libsUpgrade bind-develUpgrade bind9.16Upgrade bind-dnssec-docUpgrade bind9.16-develUpgrade bind-chrootUpgrade bind9.16-utilsUpgrade python3-bind9.16Upgrade python3-bind | Apr 15, 2024 | Feb 13, 2024 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Feb 13, 2024 |
| Amazon_linux_2023 | — | Upgrade bind-debugsourceUpgrade bind-utilsUpgrade bind-dlz-sqlite3Upgrade bind-pkcs11-debuginfoUpgrade bind-libsUpgrade bind-pkcs11-utils-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-dnssec-docUpgrade bind-dlz-filesystemUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-dlz-filesystem-debuginfoUpgrade bind-pkcs11Upgrade bind-chrootUpgrade bind-docUpgrade bindUpgrade bind-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-dlz-sqlite3-debuginfoUpgrade bind-dlz-ldap-debuginfoUpgrade bind-dlz-mysql-debuginfoUpgrade bind-dlz-ldapUpgrade bind-dnssec-utils-debuginfoUpgrade bind-dnssec-utilsUpgrade bind-licenseUpgrade bind-develUpgrade bind-libs-debuginfoUpgrade python3-bindUpgrade bind-pkcs11-develUpgrade bind-dlz-mysql | Feb 17, 2025 | Feb 13, 2024 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Feb 13, 2024 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Dell Powerstore Dsa2025050 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jan 28, 2025 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Feb 15, 2024 | Feb 15, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade bind-licenseUpgrade bind-dnssec-utilsUpgrade bindUpgrade bind-pkcs11-utilsUpgrade bind-dnssec-docUpgrade bind-chrootUpgrade bind-pkcs11Upgrade bind-libsUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade python3-bind | Jun 3, 2024 | Feb 13, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade bind-chrootUpgrade bind-utilsUpgrade bind-dnssec-docUpgrade bind-pkcs11-libsUpgrade python3-bindUpgrade bind-licenseUpgrade bind-libsUpgrade bindUpgrade bind-pkcs11Upgrade bind-dnssec-utilsUpgrade bind-pkcs11-utils | May 31, 2024 | Feb 13, 2024 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory26 | Jun 5, 2024 | Feb 13, 2024 |
| Oracle_linux | — | Upgrade bind-dnssec-docUpgrade bind9.16-docUpgrade bind-docUpgrade bind9.16-develUpgrade bind-utilsUpgrade bind9.16-libsUpgrade bind-dnssec-utilsUpgrade bind-chrootUpgrade bindUpgrade bind-develUpgrade python3-bind9.16Upgrade bind9.16-licenseUpgrade bind9.16-chrootUpgrade bind-licenseUpgrade bind-libsUpgrade bind-dyndb-ldapUpgrade python3-bindUpgrade bind9.16Upgrade bind9.16-utilsUpgrade bind9.16-dnssec-utils | Apr 12, 2024 | Feb 13, 2024 |
| Redhat_linux | — | Upgrade python3-bind9.16Upgrade bind9.16-debuginfoUpgrade bind-dyndb-ldapUpgrade bind-dyndb-ldap-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind-debuginfoUpgrade bind9.16-utilsUpgrade bind9.16-debugsourceUpgrade bind9.16-licenseUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind-libsUpgrade bind9.16-dnssec-utilsUpgrade bind-licenseUpgrade bind9.16-utils-debuginfoUpgrade bindUpgrade bind-develUpgrade bind-dyndb-ldap-debugsourceUpgrade bind-libs-debuginfoUpgrade python3-bindUpgrade bind9.16-libs-debuginfoUpgrade bind9.16Upgrade bind9.16-chrootUpgrade bind9.16-develUpgrade bind9.16-docUpgrade bind-docUpgrade bind-dnssec-utilsUpgrade bind-utilsUpgrade bind-chrootUpgrade bind-debugsourceUpgrade bind-utils-debuginfoUpgrade bind9.16-libsUpgrade bind-dnssec-doc | Apr 3, 2024 | Feb 13, 2024 |
| Rocky_linux | — | Upgrade bind9.16-debugsourceUpgrade bind-libsUpgrade bind9.16-utilsUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-chrootUpgrade bind-dnssec-utils-debuginfoUpgrade bind-dyndb-ldapUpgrade bind-dyndb-ldap-debugsourceUpgrade bind-utils-debuginfoUpgrade bind9.16-utils-debuginfoUpgrade bind-libs-debuginfoUpgrade bind9.16-debuginfoUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind-dyndb-ldap-debuginfoUpgrade bind-chrootUpgrade bind9.16-libs-debuginfoUpgrade bind9.16-develUpgrade bind-develUpgrade bind-debugsourceUpgrade bind9.16-libsUpgrade bind9.16Upgrade bind-debuginfoUpgrade bindUpgrade bind-utilsUpgrade bind-dnssec-utils | May 8, 2024 | Feb 13, 2024 |
| Suse | — | Upgrade libuv1Upgrade libisccc1600Upgrade libns1604Upgrade libirs1601Upgrade python3-bindUpgrade libisccfg1600Upgrade libdns1605Upgrade libisc1606Upgrade bind-develUpgrade bind-chrootenvUpgrade libirs-develUpgrade libuv-develUpgrade libbind9-1600Upgrade bind-docUpgrade bind-utilsUpgrade bind | Feb 22, 2024 | Feb 13, 2024 |
| Ubuntu | — | Upgrade bind9 | Feb 21, 2024 | Feb 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub