PT-2021-3137 · Isc+10 · Bind+10

Published

2021-04-28

·

Updated

2026-01-19

·

CVE-2021-25215

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND versions 9.0.0 through 9.11.29 BIND versions 9.12.0 through 9.16.13 BIND versions 9.9.3-S1 through 9.11.29-S1 BIND versions 9.16.8-S1 through 9.16.13-S1 BIND versions 9.17.0 through 9.17.11
Description The issue is related to an assertion failure in the named process when receiving a query for a record, which can cause the process to terminate. This can be triggered by a remote attacker, leading to a denial of service. The vulnerability affects all currently maintained BIND 9 branches. It is also related to the use of GSS-TSIG features, which can render a server vulnerable if explicitly configured. The estimated number of potentially affected devices is not specified.
Recommendations For BIND versions 9.0.0 through 9.11.29, update to a version that is not affected by this issue. For BIND versions 9.12.0 through 9.16.13, update to a version that is not affected by this issue. For BIND versions 9.9.3-S1 through 9.11.29-S1, update to a version that is not affected by this issue. For BIND versions 9.16.8-S1 through 9.16.13-S1, update to a version that is not affected by this issue. For BIND versions 9.17.0 through 9.17.11, update to a version that is not affected by this issue. As a temporary workaround, consider disabling the use of GSS-TSIG features to minimize the risk of exploitation.

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1752
ALT-PU-2021-1786
ALT-PU-2021-1836
BDU:2021-02778
CESA-2021_1469
CESA-2021_1989
CVE-2021-25215
DLA-2647-1
DSA-4909-1
MGASA-2021-0220
OESA-2021-1206
OESA-2022-1993
OPENSUSE-SU-2021:0668-1
OPENSUSE-SU-2021:1826-1
OPENSUSE-SU-2021_0668-1
OPENSUSE-SU-2021_1826-1
OPENSUSE-SU-2024:10650-1
RHSA-2021:1468
RHSA-2021:1469
RHSA-2021:1475
RHSA-2021:1476
RHSA-2021:1477
RHSA-2021:1478
RHSA-2021:1479
RHSA-2021:1989
RHSA-2021:2024
RHSA-2021:2028
RHSA-2021_1468
RHSA-2021_1469
RHSA-2021_1989
RLSA-2021:1989
SUSE-SU-2021:1468-1
SUSE-SU-2021:1469-1
SUSE-SU-2021:1471-1
SUSE-SU-2021:14714-1
SUSE-SU-2021:1826-1
SUSE-SU-2021_1468-1
SUSE-SU-2021_1469-1
SUSE-SU-2021_1471-1
SUSE-SU-2021_14714-1
USN-4929-1
USN-7739-1

Affected Products

Alt Linux
Astra Linux
Bind
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu