CVE-2020-8621
published 2020-08-21CVE-2020-8621: In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.94%
85.6th percentile
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bind9 | < bind9 1:9.16.6-1 (bookworm) | bind9 1:9.16.6-1 (bookworm) |
| isc | bind | 9.14.0 – 9.16.5 | — |
| isc | bind | 9.17.0 – 9.17.3 | — |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.16.6-1 | 1:9.16.6-1 |
| isc | bind9 | >= 0 < 1:9.10.3.dfsg.P4-8ubuntu1.17 | 1:9.10.3.dfsg.P4-8ubuntu1.17 |
| isc | bind9 | >= 0 < 1:9.11.3+dfsg-1ubuntu1.13 | 1:9.11.3+dfsg-1ubuntu1.13 |
| isc | bind9 | >= 0 < 1:9.16.1-0ubuntu2.3 | 1:9.16.1-0ubuntu2.3 |
| isc | bind9 | >= 9.14.0 < * | * |
| msrc | cm1_bind_9.16.3-2_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| synology | dns_server | < 2.2.2-5027 | 2.2.2-5027 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7vc6-qmjj-2j83: In BIND 9
ghsa_unreviewed·2022-05-24
CVE-2020-8621 [MEDIUM] CWE-20 GHSA-7vc6-qmjj-2j83: In BIND 9
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
OSV
CVE-2020-8621: In BIND 9
osv·2020-08-21·CVSS 7.5
CVE-2020-8621 [HIGH] CVE-2020-8621: In BIND 9
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
OSV
bind9 vulnerabilities
osv·2020-08-21·CVSS 7.5
CVE-2020-8620 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Emanuel Almeida discovered that Bind incorrectly handled certain TCP
payloads. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-8620)
Joseph Gullo discovered that Bind incorrectly handled QNAME minimization
when used in certain configurations. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-8621)
Dave Feldman, Jeff Warren, and Joel Cunningham discovered that Bind
incorrectly handled certain truncated responses to a TSIG-signed request. A
remote attacker could possibly use this issue to cause Bind to crash,
resulting in a denial of service. (CVE-202
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2020-08-21·CVSS 7.5
CVE-2020-8620 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Emanuel Almeida discovered that Bind incorrectly handled certain TCP
payloads. A remote attacker could possibly use this issue to cause Bind to
crash, resulting in a denial of service. This issue only affected Ubuntu
20.04 LTS. (CVE-2020-8620)
Joseph Gullo discovered that Bind incorrectly handled QNAME minimization
when used in certain configurations. A remote attacker could possibly use
this issue to cause Bind to crash, resulting in a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2020-8621)
Dave Feldman, Jeff Warren, and Joel Cunningham discovered that Bind
incorrectly handled certain truncated responses to a TSIG-signed request. A
remote attacker could possibly use this issue to cau
Red Hat
bind: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
vendor_redhat·2020-08-20·CVSS 7.5
CVE-2020-8621 [HIGH] CWE-400 bind: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
bind: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
Statement: This flaw only affects bind >= 9.14.x. Therefore versions of bind package shipped with Red Hat Enterprise Linux are not affected by this flaw.
Package: bind (Red Hat Enterprise Linux 5) - Not affected
Package: bind97 (Red Hat Enterprise Linux 5) - Not affected
Package: bind (Red Hat Enterprise Linux 6) - Not affected
Package: bind (Red Hat Enterprise Linux 7) - Not affected
Package: bind (Red Hat
Microsoft
Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
vendor_msrc·2020-08-11·CVSS 7.5
CVE-2020-8621 [HIGH] CWE-617 Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Remediation: CBL-Mariner
Debian
CVE-2020-8621: bind9 - In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both ...
vendor_debian·2020·CVSS 7.5
CVE-2020-8621 [HIGH] CVE-2020-8621: bind9 - In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both ...
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
Scope: local
bookworm: resolved (fixed in 1:9.16.6-1)
bullseye: resolved (fixed in 1:9.16.6-1)
forky: resolved (fixed in 1:9.16.6-1)
sid: resolved (fixed in 1:9.16.6-1)
trixie: resolved (fixed in 1:9.16.6-1)
No detection rules found.
No public exploits indexed.
arXiv
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
arxiv_fulltext·2023-10-04
ResolverFuzz: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
: Automated Discovery of DNS Resolver Vulnerabilities with Query-Response Fuzzing
https://faculty.sites.uci.edu/zhouli/research/ Qifan Zhang ,
https://faculty.sites.uci.edu/zhouli/research/ Xuesong Bai ,
https://netsec.ccert.edu.cn/people/lx19 Xiang Li ,
https://netsec.ccert.edu.cn/people/duanhx/ Haixin Duan ,
https://netsec.ccert.edu.cn/people/qli/ Qi Li , and
https://faculty.sites.uci.edu/zhouli/ Zhou Li
Corresponding authors. Most of Xiang Li's work was done when visiting UCI as a project specialist.
https://uci.edu/University of California, Irvine,
https://www.tsinghua.edu.cn/en/Tsinghua University
Zhongguancun Laboratory,
https://www.qcl.edu.cn/Quan Cheng Laboratory
## Abstract
Domain Name System (DNS) is a critical component of the Internet. DNS resolvers, which act as the cache
Bugzilla
CVE-2020-8621 bind: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
bugzilla·2020-08-18·CVSS 7.5
CVE-2020-8621 [HIGH] CVE-2020-8621 bind: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
CVE-2020-8621 bind: Attempting QNAME minimization after forwarding can lead to an assertion failure in resolver.c
As per upstream advisory:
While query forwarding and QNAME minimization are mutually incompatible, BIND did sometimes allow QNAME minimization when continuing with recursion after 'forward first' did not result in an answer. In these cases the data used by QNAME minimization might be inconsistent, leading to an assertion failure, causing the server to exit.
If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash.
Servers that 'forward only' are not affected
Discussion:
Acknowledgments:
Name: ISC
Upstream: Joseph Gullo
---
Statement:
T
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8621https://security.gentoo.org/glsa/202008-19https://security.netapp.com/advisory/ntap-20200827-0003/https://usn.ubuntu.com/4468-1/https://www.synology.com/security/advisory/Synology_SA_20_19http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlhttps://kb.isc.org/docs/cve-2020-8621https://security.gentoo.org/glsa/202008-19https://security.netapp.com/advisory/ntap-20200827-0003/https://usn.ubuntu.com/4468-1/https://www.synology.com/security/advisory/Synology_SA_20_19
2020-08-21
Published