CVE-2016-2848
published 2016-10-21CVE-2016-2848: ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via…
PriorityP346high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
25.77%
97.7th percentile
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.9.3.dfsg.P2-1 (bookworm) | bind9 1:9.9.3.dfsg.P2-1 (bookworm) |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
| isc | bind | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Trigger condition: BIND named process crashes with an assertion failure upon receiving a DNS packet containing a malformed OPT resource record options section. Both authoritative and recursive server configurations are vulnerable. ↗
- →Detection focus: monitor for unexpected named (BIND) process termination accompanied by assertion failure messages in logs, triggered by inbound DNS packets with malformed OPT RR options data. ↗
- →Patch reference: the fix is BIND change #3548, corresponding to upstream commit 4adf97c32fcca7d00e5756607fd045f2aab9c3d4. Systems not containing this change are vulnerable. ↗
- ·Affected BIND versions are 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2; both authoritative and recursive server roles are vulnerable. ↗
- ·Red Hat Enterprise Linux 7 is listed as Not Affected; RHEL 4 is Will Not Fix. Debian resolved the issue in package version 1:9.9.3.dfsg.P2-1. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j4vg-xpv6-9x2m: ISC BIND 9
ghsa_unreviewed·2022-05-14
CVE-2016-2848 [HIGH] CWE-20 GHSA-j4vg-xpv6-9x2m: ISC BIND 9
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
OSV
CVE-2016-2848: ISC BIND 9
osv·2016-10-21·CVSS 7.5
CVE-2016-2848 [HIGH] CVE-2016-2848: ISC BIND 9
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
Ubuntu
Bind vulnerability
vendor_ubuntu·2016-10-21
CVE-2016-2848 Bind vulnerability
Title: Bind vulnerability
Summary: Bind could be made to crash if it received specially crafted network
traffic.
Toshifumi Sakaguchi discovered that Bind incorrectly handled certain
packets with malformed options. A remote attacker could possibly use this
issue to cause Bind to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bind: assertion failure triggered by a packet with malformed options
vendor_redhat·2016-10-20·CVSS 7.5
CVE-2016-2848 [HIGH] CWE-617 bind: assertion failure triggered by a packet with malformed options
bind: assertion failure triggered by a packet with malformed options
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
A denial of service flaw was found in the way BIND handled packets with malformed options. A remote attacker could use this flaw to make named exit unexpectedly with an assertion failure via a specially crafted DNS packet.
Package: bind (Red Hat Enterprise Linux 4) - Will not fix
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2016-2848: bind9 - ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attacke...
vendor_debian·2016·CVSS 7.5
CVE-2016-2848 [HIGH] CVE-2016-2848: bind9 - ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attacke...
ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record.
Scope: local
bookworm: resolved (fixed in 1:9.9.3.dfsg.P2-1)
bullseye: resolved (fixed in 1:9.9.3.dfsg.P2-1)
forky: resolved (fixed in 1:9.9.3.dfsg.P2-1)
sid: resolved (fixed in 1:9.9.3.dfsg.P2-1)
trixie: resolved (fixed in 1:9.9.3.dfsg.P2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-2848 bind: assertion failure triggered by a packet with malformed options
bugzilla·2016-10-17·CVSS 7.5
CVE-2016-2848 [HIGH] CVE-2016-2848 bind: assertion failure triggered by a packet with malformed options
CVE-2016-2848 bind: assertion failure triggered by a packet with malformed options
A packet with a malformed options section can be used to deliberately trigger an assertion failure affecting versions of BIND which do not contain change #3548.
A server vulnerable to this defect can be forced to exit with an assertion failure if it receives a malformed packet. Authoritative and recursive servers are both vulnerable.
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=blob;f=CHANGES has more information on change #3548. The commit corresponding to this change is https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=4adf97c32fcca7d00e5756607fd045f2aab9c3d4.
Discussion:
Upstream commit:
https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git;a=commitdiff;h=4adf97c32fcca7
Greynoiseio
NoiseLetter February 2026
blogs_greynoiseio
NoiseLetter February 2026
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
http://rhn.redhat.com/errata/RHSA-2016-2093.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2094.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2099.htmlhttp://www.securityfocus.com/bid/93809http://www.securityfocus.com/bid/93814http://www.securitytracker.com/id/1037073https://bugzilla.redhat.com/show_bug.cgi?id=1385450https://kb.isc.org/article/AA-01433/74/CVE-2016-2848https://security.netapp.com/advisory/ntap-20180926-0002/https://security.netapp.com/advisory/ntap-20180926-0005/https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git%3Ba=commit%3Bh=4adf97c32fcca7d00e5756607fd045f2aab9c3d4http://rhn.redhat.com/errata/RHSA-2016-2093.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2094.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2099.htmlhttp://www.securityfocus.com/bid/93809http://www.securityfocus.com/bid/93814http://www.securitytracker.com/id/1037073https://bugzilla.redhat.com/show_bug.cgi?id=1385450https://kb.isc.org/article/AA-01433/74/CVE-2016-2848https://security.netapp.com/advisory/ntap-20180926-0002/https://security.netapp.com/advisory/ntap-20180926-0005/https://source.isc.org/cgi-bin/gitweb.cgi?p=bind9.git%3Ba=commit%3Bh=4adf97c32fcca7d00e5756607fd045f2aab9c3d4
2016-10-21
Published