To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continuously processing query patterns triggering this type of cache-database maintenance, `named` may not be able to handle the cleanup events in a timely manner. This in turn enables the list of queued cleanup events to grow infinitely large over time, allowing the configured `max-cache-size` limit to be significantly exceeded. This issue affects BIND 9 versions 9.16.0 through 9.16.45 and 9.16.8-S1 through 9.16.45-S1.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade bind9.16-utilsUpgrade python3-bind9.16Upgrade bind9.16-develUpgrade bind-dnssec-docUpgrade bind9.16Upgrade bind-chrootUpgrade python3-bindUpgrade bind-utilsUpgrade bind-libsUpgrade bind-develUpgrade bind-dyndb-ldapUpgrade bind9.16-chrootUpgrade bind9.16-libsUpgrade bind9.16-licenseUpgrade bind-dnssec-utilsUpgrade bind9.16-docUpgrade bindUpgrade bind-licenseUpgrade bind9.16-dnssec-utilsUpgrade bind-doc | Apr 15, 2024 | Feb 13, 2024 |
| Alpine Linux | — | Upgrade bind | Mar 26, 2024 | Feb 13, 2024 |
| Amazon_linux_2023 | — | Upgrade bind-docUpgrade bind-dnssec-docUpgrade bind-utils-debuginfoUpgrade bind-debuginfoUpgrade bind-debugsourceUpgrade bind-dlz-filesystem-debuginfoUpgrade bind-pkcs11-debuginfoUpgrade bind-pkcs11-utilsUpgrade bind-libsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-libs-debuginfoUpgrade bind-pkcs11-utils-debuginfoUpgrade bindUpgrade bind-dlz-filesystemUpgrade bind-pkcs11Upgrade bind-chrootUpgrade bind-utilsUpgrade bind-dlz-sqlite3Upgrade bind-dlz-ldapUpgrade bind-libs-debuginfoUpgrade bind-dlz-mysql-debuginfoUpgrade bind-dnssec-utils-debuginfoUpgrade bind-dlz-sqlite3-debuginfoUpgrade bind-develUpgrade python3-bindUpgrade bind-dlz-mysqlUpgrade bind-dlz-ldap-debuginfoUpgrade bind-pkcs11-develUpgrade bind-dnssec-utilsUpgrade bind-license | Feb 17, 2025 | Feb 13, 2024 |
| Debian | — | Upgrade bind9 | Jul 30, 2024 | Feb 13, 2024 |
| Dell Powerstore Dsa2024462 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Nov 20, 2024 |
| Dell Powerstore Dsa2024497 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Dec 19, 2024 |
| Dell Powerstore Dsa2025050 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Jan 28, 2025 |
| Dns Bind | — | Upgrade ISC BIND to latest version | Feb 15, 2024 | Feb 15, 2024 |
| Huawei Euleros 2_0_sp11 | — | Upgrade bindUpgrade bind-pkcs11-utilsUpgrade bind-licenseUpgrade bind-dnssec-utilsUpgrade bind-pkcs11-libsUpgrade bind-libsUpgrade bind-chrootUpgrade python3-bindUpgrade bind-pkcs11Upgrade bind-utilsUpgrade bind-dnssec-doc | Jun 3, 2024 | Feb 13, 2024 |
| Huawei Euleros 2_0_sp12 | — | Upgrade bind-dnssec-docUpgrade bind-chrootUpgrade python3-bindUpgrade bind-utilsUpgrade bind-pkcs11-libsUpgrade bind-pkcs11-utilsUpgrade bindUpgrade bind-licenseUpgrade bind-pkcs11Upgrade bind-libsUpgrade bind-dnssec-utils | May 31, 2024 | Feb 13, 2024 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory26 | Jun 5, 2024 | Feb 13, 2024 |
| Oracle_linux | — | Upgrade bind9.16-docUpgrade bind-docUpgrade bind-dnssec-docUpgrade bind-utilsUpgrade bind9.16-develUpgrade bind9.16-libsUpgrade bind-dnssec-utilsUpgrade bind-chrootUpgrade bindUpgrade bind9.16-utilsUpgrade bind9.16Upgrade bind-licenseUpgrade bind-libsUpgrade bind9.16-dnssec-utilsUpgrade python3-bind9.16Upgrade bind-dyndb-ldapUpgrade python3-bindUpgrade bind9.16-chrootUpgrade bind9.16-licenseUpgrade bind-devel | Apr 12, 2024 | Feb 13, 2024 |
| Redhat_linux | — | Upgrade bind-docUpgrade bind9.16-develUpgrade bind-debugsourceUpgrade bind9.16-docUpgrade bind-utilsUpgrade bind-dnssec-utilsUpgrade bind-chrootUpgrade bind-dnssec-docUpgrade bind9.16-libsUpgrade bind-utils-debuginfoUpgrade bind9.16-debugsourceUpgrade bind-dyndb-ldap-debuginfoUpgrade bindUpgrade bind-licenseUpgrade bind-libsUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind9.16-libs-debuginfoUpgrade bind9.16-licenseUpgrade bind-dyndb-ldapUpgrade bind-debuginfoUpgrade python3-bind9.16Upgrade bind-dnssec-utils-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-chrootUpgrade bind-develUpgrade python3-bindUpgrade bind9.16-dnssec-utilsUpgrade bind9.16-utilsUpgrade bind-libs-debuginfoUpgrade bind9.16Upgrade bind9.16-debuginfo | Apr 3, 2024 | Feb 13, 2024 |
| Rocky_linux | — | Upgrade bind-libsUpgrade bind9.16-utilsUpgrade bind-utils-debuginfoUpgrade bind9.16-dnssec-utils-debuginfoUpgrade bind-dyndb-ldap-debugsourceUpgrade bind9.16-utils-debuginfoUpgrade bind9.16-debuginfoUpgrade bind-dyndb-ldapUpgrade bind9.16-chrootUpgrade bind9.16-dnssec-utilsUpgrade bind-dnssec-utils-debuginfoUpgrade bind9.16-debugsourceUpgrade bind-libs-debuginfoUpgrade bind-dyndb-ldap-debuginfoUpgrade bind9.16-libsUpgrade bind9.16Upgrade bind9.16-libs-debuginfoUpgrade bind-chrootUpgrade bind-develUpgrade bindUpgrade bind-utilsUpgrade bind-debugsourceUpgrade bind-dnssec-utilsUpgrade bind-debuginfoUpgrade bind9.16-devel | May 8, 2024 | Feb 13, 2024 |
| Suse | — | Upgrade libirs-develUpgrade libisccfg1600Upgrade libisc1606Upgrade libdns1605Upgrade libirs1601Upgrade libisccc1600Upgrade python3-bindUpgrade libns1604Upgrade libuv-develUpgrade libbind9-1600Upgrade bind-chrootenvUpgrade bind-develUpgrade libuv1Upgrade bind-utilsUpgrade bind-docUpgrade bind | Feb 22, 2024 | Feb 13, 2024 |
| Ubuntu | — | Upgrade bind9 | Feb 21, 2024 | Feb 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Feb 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub