PT-2021-6075 · Isc+12 · Bind+12

Published

2021-10-27

·

Updated

2025-06-23

·

CVE-2021-25219

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions BIND versions 9.3.0 through 9.11.35 BIND versions 9.12.0 through 9.16.21 BIND Supported Preview Edition versions 9.9.3-S1 through 9.11.35-S1 BIND Supported Preview Edition versions 9.16.8-S1 through 9.16.21-S1 BIND 9.17 development branch versions 9.17.0 through 9.17.18
Description Exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The lame cache's internal data structures can grow almost infinitely, potentially causing significant delays in client query processing. This issue is related to an uncontrolled consumption of resources, which may allow a remote attacker to cause a denial of service.
Recommendations For BIND versions 9.3.0 through 9.11.35, update to a version outside of this range to resolve the issue. For BIND versions 9.12.0 through 9.16.21, update to a version outside of this range to resolve the issue. For BIND Supported Preview Edition versions 9.9.3-S1 through 9.11.35-S1, update to a version outside of this range to resolve the issue. For BIND Supported Preview Edition versions 9.16.8-S1 through 9.16.21-S1, update to a version outside of this range to resolve the issue. For BIND 9.17 development branch versions 9.17.0 through 9.17.18, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the growth of the lame cache's internal data structures to prevent significant delays in client query processing.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:2092
ALT-PU-2021-3144
ALT-PU-2021-3238
ALT-PU-2021-3307
ALT-PU-2021-3377
ALT-PU-2025-8034
AZL-6327
BDU:2022-00686
CESA-2022_2092
CVE-2021-25219
DLA-2807-1
DSA-4994-1
MGASA-2021-0560
OESA-2021-1459
OESA-2022-1993
OPENSUSE-SU-2021:1502-1
OPENSUSE-SU-2021:3773-1
OPENSUSE-SU-2021_1502-1
OPENSUSE-SU-2021_3773-1
OPENSUSE-SU-2022:0151-1
OPENSUSE-SU-2022_0151-1
OPENSUSE-SU-2022_2713-1
OPENSUSE-SU-2024:11660-1
RHSA-2022:2092
RHSA-2022_2092
RLSA-2022:2092
SUSE-SU-2021:3657-1
SUSE-SU-2021:3773-1
SUSE-SU-2021_3657-1
SUSE-SU-2021_3773-1
SUSE-SU-2022:0151-1
SUSE-SU-2022:2713-1
SUSE-SU-2022_0151-1
SUSE-SU-2022_2713-1
USN-5126-1
USN-5126-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind
Bind Server
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu