PT-2021-3136 · Isc+10 · Bind+10

Greg Kuechle

·

Published

2021-04-28

·

Updated

2026-01-29

·

CVE-2021-25214

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions 9.8.5 through 9.8.8 BIND versions 9.9.3 through 9.11.29 BIND versions 9.12.0 through 9.16.13 BIND 9 Supported Preview Edition versions 9.9.3-S1 through 9.11.29-S1 BIND 9 Supported Preview Edition versions 9.16.8-S1 through 9.16.13-S1 BIND 9.17 development branch versions 9.17.0 through 9.17.11
Description The issue is related to insufficient use of the assert() function in the BIND server, which can be exploited by a remote attacker to cause a denial of service using a specially crafted request. When a vulnerable version of named receives a malformed IXFR, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.
Recommendations For BIND versions 9.8.5 through 9.8.8, update to a version outside of this range to resolve the issue. For BIND versions 9.9.3 through 9.11.29, update to a version outside of this range to resolve the issue. For BIND versions 9.12.0 through 9.16.13, update to a version outside of this range to resolve the issue. For BIND 9 Supported Preview Edition versions 9.9.3-S1 through 9.11.29-S1, update to a version outside of this range to resolve the issue. For BIND 9 Supported Preview Edition versions 9.16.8-S1 through 9.16.13-S1, update to a version outside of this range to resolve the issue. For BIND 9.17 development branch versions 9.17.0 through 9.17.11, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of the named process to minimize the risk of exploitation.

Fix

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:4384
ALT-PU-2021-1752
ALT-PU-2021-1786
ALT-PU-2021-1836
BDU:2021-02777
CESA-2021_3325
CESA-2021_4384
CVE-2021-25214
DLA-2647-1
DSA-4909-1
MGASA-2021-0220
MGASA-2021-0275
OESA-2021-1206
OESA-2022-1993
OPENSUSE-SU-2021:0668-1
OPENSUSE-SU-2021:1826-1
OPENSUSE-SU-2021_0668-1
OPENSUSE-SU-2021_1826-1
OPENSUSE-SU-2024:10650-1
RHSA-2021:3325
RHSA-2021:4384
RHSA-2021_3325
RHSA-2021_4384
RLSA-2021:4384
SUSE-SU-2021:1468-1
SUSE-SU-2021:1469-1
SUSE-SU-2021:1471-1
SUSE-SU-2021:14714-1
SUSE-SU-2021:1826-1
SUSE-SU-2021_1468-1
SUSE-SU-2021_1469-1
SUSE-SU-2021_1471-1
SUSE-SU-2021_14714-1
SUSE-SU-2021_1826-1
USN-4929-1
USN-7739-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind
Bind Server
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu