An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. This issue affects BIND 9 versions 9.18.36 through 9.18.48, 9.20.8 through 9.20.22, 9.21.7 through 9.21.21, 9.18.36-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade bind | May 25, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade bind-pkcs11-libsUpgrade bind-licenseUpgrade bind-export-libsUpgrade bind-pkcs11-develUpgrade bind-sdb-chrootUpgrade bindUpgrade bind-chrootUpgrade bind-lite-develUpgrade bind-utilsUpgrade bind-export-develUpgrade bind-pkcs11Upgrade bind-debuginfoUpgrade bind-sdbUpgrade bind-develUpgrade bind-pkcs11-utilsUpgrade bind-libs-liteUpgrade bind-libs | Jun 9, 2026 | Jun 9, 2026 |
| Amazon_linux_2023 | — | Upgrade bind-debugsourceUpgrade bind-licenseUpgrade bind-dnssec-utilsUpgrade bindUpgrade bind-docUpgrade bind-debuginfoUpgrade bind-utils-debuginfoUpgrade bind-libs-debuginfoUpgrade bind-chrootUpgrade bind-dnssec-utils-debuginfoUpgrade bind-utilsUpgrade bind-develUpgrade bind-libs | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade bind9 | May 24, 2026 | May 24, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Aug 13, 2026 | Aug 12, 2026 |
| Ibm Aix | — | Apply the fix or workaround for bind_advisory30 | Jun 29, 2026 | Jun 29, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | May 26, 2026 |
| Ubuntu | — | Upgrade bind9 | May 25, 2026 | May 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub