PT-2021-7348 · Isc+13 · Bind+13

Baojun Liu

+3

·

Published

2021-01-15

·

Updated

2026-01-30

·

CVE-2021-25220

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions BIND versions 9.11.0 through 9.11.36 BIND versions 9.12.0 through 9.16.26 BIND versions 9.17.0 through 9.18.0 BIND Supported Preview Editions versions 9.11.4-S1 through 9.11.36-S1 BIND Supported Preview Editions versions 9.16.8-S1 through 9.16.26-S1 BIND versions prior to 9.11.0, including Supported Preview Editions, are also believed to be affected but have not been tested as they are EOL.
Description The issue is related to the handling of DNS queries, which could allow an attacker to poison the cache with incorrect records. This might lead to queries being made to the wrong servers and result in false information being returned to clients. The problem is associated with errors when using DNS forwarders.
Recommendations For BIND versions 9.11.0 through 9.11.36, update to a version outside of this range to resolve the issue. For BIND versions 9.12.0 through 9.16.26, update to a version outside of this range to resolve the issue. For BIND versions 9.17.0 through 9.18.0, update to a version outside of this range to resolve the issue. For BIND Supported Preview Editions versions 9.11.4-S1 through 9.11.36-S1, update to a version outside of this range to resolve the issue. For BIND Supported Preview Editions versions 9.16.8-S1 through 9.16.26-S1, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting the use of DNS forwarders to minimize the risk of cache poisoning.

Fix

Assertion Failure

Improper Resource Release

HTTP Request/Response Smuggling

Weakness Enumeration

Related Identifiers

ALSA-2022:7643
ALSA-2022:7790
ALSA-2022:8068
ALSA-2022:8385
ALT-PU-2022-1501
ALT-PU-2022-1529
ALT-PU-2022-1568
ALT-PU-2022-1608
ALT-PU-2025-7945
ALT-PU-2025-8034
AZL-9118
BDU:2022-05754
BDU:2023-02158
BDU:2023-02160
BDU:2023-02161
CESA-2022_7643
CESA-2022_7790
CESA-2023_0402
CVE-2021-25220
DLA-2955-1
DLA-2955-2
DSA-5105-1
MGASA-2022-0108
OESA-2022-1615
OESA-2022-1993
OPENSUSE-SU-2022:0945-1
OPENSUSE-SU-2022:0946-1
OPENSUSE-SU-2022_0945-1
OPENSUSE-SU-2022_0946-1
OPENSUSE-SU-2022_2713-1
OPENSUSE-SU-2024:12081-1
RHSA-2022:7643
RHSA-2022:7790
RHSA-2022:8068
RHSA-2022:8385
RHSA-2022_7643
RHSA-2022_7790
RHSA-2022_8068
RHSA-2022_8385
RHSA-2023:0402
RHSA-2023_0402
RHSA-2024:2720
RHSA-2025:21740
RHSA-2025:21741
RHSA-2025:21889
RHSA-2025:22168
RHSA-2025:23414
RLSA-2022:7643
RLSA-2022:7790
RLSA-2022:8068
RLSA-2022:8385
ROSA-SA-2023-2121
SUSE-SU-2022:0908-1
SUSE-SU-2022:0945-1
SUSE-SU-2022:0946-1
SUSE-SU-2022:1616-1
SUSE-SU-2022:2713-1
SUSE-SU-2022_0908-1
SUSE-SU-2022_0945-1
SUSE-SU-2022_0946-1
SUSE-SU-2022_1616-1
USN-5332-1
USN-5332-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Bind
Bind Server
Centos
Ibm Aix
Junos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu