cbcvebase.

Debian Bind9 vulnerabilities

127 known vulnerabilities affecting debian/bind9.

Total CVEs
127
CISA KEV
0
Public exploits
7
Exploited in wild
4
Severity breakdown
HIGH73MEDIUM35LOW19

Vulnerabilities

Page 2 of 7
CVE-2015-4620P3HIGHCVSS 7.8fixed in bind9 1:9.9.5.dfsg-10 (bookworm)2015
CVE-2015-4620 [HIGH] CVE-2015-4620: bind9 - name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x befor... name.c in named in ISC BIND 9.7.x through 9.9.x before 9.9.7-P1 and 9.10.x before 9.10.2-P2, when configured as a recursive resolver with DNSSEC validation, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) by constructing crafted zone data and then making a query for a name in that zone. Scope: local bookworm: resolved (fi
debian
CVE-2013-2266P3HIGHCVSS 7.8fixed in bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm)2013
CVE-2013-2266 [HIGH] CVE-2013-2266: bind9 - libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x ... libdns in ISC BIND 9.7.x and 9.8.x before 9.8.4-P2, 9.8.5 before 9.8.5b2, 9.9.x before 9.9.2-P2, and 9.9.3 before 9.9.3b2 on UNIX platforms allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression, as demonstrated by a memory-exhaustion attack against a machine running a named process. Scope: local bookworm: resolved (fi
debian
CVE-2016-2775P3MEDIUMCVSS 5.9fixed in bind9 1:9.10.3.dfsg.P4-11 (bookworm)2016
CVE-2016-2775 [MEDIUM] CVE-2016-2775: bind9 - ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b... ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol. Scope: local bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-11) bullseye: resolved (fixed in 1:9.10.3.dfsg
debian
CVE-2024-11187P3HIGHCVSS 7.5fixed in bind9 1:9.18.33-1~deb12u2 (bookworm)2024
CVE-2024-11187 [HIGH] CVE-2024-11187: bind9 - It is possible to construct a zone such that some queries to it will generate re... It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately craft
debian
CVE-2025-8677P3HIGHCVSS 7.5fixed in bind9 1:9.18.41-1~deb12u1 (bookworm)2025
CVE-2025-8677 [HIGH] CVE-2025-8677: bind9 - Querying for records within a specially crafted zone containing certain malforme... Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1. Scope: local bookworm: resolved (fixed in 1:9.18.41-1~deb12u1) bullseye: re
debian
CVE-2020-8616P3HIGHCVSS 8.6fixed in bind9 1:9.16.3-1 (bookworm)2020
CVE-2020-8616 [HIGH] CVE-2020-8616: bind9 - A malicious actor who intentionally exploits this lack of effective limitation o... A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing s
debian
CVE-2015-5722P3HIGHCVSS 7.8fixed in bind9 1:9.9.5.dfsg-12 (bookworm)2015
CVE-2015-5722 [HIGH] CVE-2015-5722: bind9 - buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 al... buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone. Scope: local bookworm: resolved (fixed in 1:9.9.5.dfsg-12) bullseye: resolved (fixed in 1:9.9.5.dfsg-12) fo
debian
CVE-2022-3924P3HIGHCVSS 7.5fixed in bind9 1:9.18.11-1 (bookworm)2022
CVE-2022-3924 [HIGH] CVE-2022-3924: bind9 - This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also... This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If there are sufficient
debian
CVE-2025-13878P3HIGHCVSS 7.5fixed in bind9 1:9.18.44-1~deb12u1 (bookworm)2025
CVE-2025-13878 [HIGH] CVE-2025-13878: bind9 - Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This is... Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1. Scope: local bookworm: resolved (fixed in 1:9.18.44-1~deb12u1) bullseye: resolved forky: resolved (fixed in 1:9.20.18-1)
debian
CVE-2025-40778P3HIGHCVSS 8.6fixed in bind9 1:9.18.41-1~deb12u1 (bookworm)2025
CVE-2025-40778 [HIGH] CVE-2025-40778: bind9 - Under certain circumstances, BIND is too lenient when accepting records from ans... Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
debian
CVE-2025-40780P3HIGHCVSS 8.6fixed in bind9 1:9.18.41-1~deb12u1 (bookworm)2025
CVE-2025-40780 [HIGH] CVE-2025-40780: bind9 - In specific circumstances, due to a weakness in the Pseudo Random Number Generat... In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 thr
debian
CVE-2022-3094P3HIGHCVSS 7.5fixed in bind9 1:9.18.11-1 (bookworm)2022
CVE-2022-3094 [HIGH] CVE-2022-3094: bind9 - Sending a flood of dynamic DNS updates may cause `named` to allocate large amoun... Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update from a client who
debian
CVE-2021-25215P3HIGHCVSS 7.5fixed in bind9 1:9.16.15-1 (bookworm)2021
CVE-2021-25215 [HIGH] CVE-2021-25215: bind9 - In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.... In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due
debian
CVE-2012-4244P3HIGHCVSS 7.8fixed in bind9 1:9.8.4.dfsg-1 (bookworm)2012
CVE-2012-4244 [HIGH] CVE-2012-4244: bind9 - ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and ... ISC BIND 9.x before 9.7.6-P3, 9.8.x before 9.8.3-P3, 9.9.x before 9.9.1-P3, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P3 allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a long resource record. Scope: local bookworm: resolved (fixed in 1:9.8.4.dfsg-1) bullseye: resolved (fixed in 1:9.8.4.dfsg-1) forky: resolv
debian
CVE-2025-40775P3LOWCVSS 7.5fixed in bind9 1:9.20.9-1 (forky)2025
CVE-2025-40775 [HIGH] CVE-2025-40775: bind9 - When an incoming DNS protocol message includes a Transaction Signature (TSIG), B... When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7. Scope: local bookworm: resolved bullseye: resolved forky: resolved (fix
debian
CVE-2016-9444P3HIGHCVSS 7.5fixed in bind9 1:9.10.3.dfsg.P4-11 (bookworm)2016
CVE-2016-9444 [HIGH] CVE-2016-9444: bind9 - named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x befor... named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer. Scope: local bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-11) bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-11) forky: resolved (fixed in 1:9.1
debian
CVE-2012-5166P3HIGHCVSS 7.8fixed in bind9 1:9.8.1.dfsg.P1-4.3 (bookworm)2012
CVE-2012-5166 [HIGH] CVE-2012-5166: bind9 - ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and ... ISC BIND 9.x before 9.7.6-P4, 9.8.x before 9.8.3-P4, 9.9.x before 9.9.1-P4, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P4 allows remote attackers to cause a denial of service (named daemon hang) via unspecified combinations of resource records. Scope: local bookworm: resolved (fixed in 1:9.8.1.dfsg.P1-4.3) bullseye: resolved (fixed in 1:9.8.1.dfsg.P1-4.3) forky: resolved
debian
CVE-2012-3817P3HIGHCVSS 7.8fixed in bind9 1:9.8.1.dfsg.P1-4.2 (bookworm)2012
CVE-2012-3817 [HIGH] CVE-2012-3817: bind9 - ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; ... ISC BIND 9.4.x, 9.5.x, 9.6.x, and 9.7.x before 9.7.6-P2; 9.8.x before 9.8.3-P2; 9.9.x before 9.9.1-P2; and 9.6-ESV before 9.6-ESV-R7-P2, when DNSSEC validation is enabled, does not properly initialize the failing-query cache, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) by sending many queries. Scope: local bookworm: res
debian
CVE-2012-1667P3HIGHCVSS 8.5fixed in bind9 1:9.8.1.dfsg.P1-4.1 (bookworm)2012
CVE-2012-1667 [HIGH] CVE-2012-1667: bind9 - ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and ... ISC BIND 9.x before 9.7.6-P1, 9.8.x before 9.8.3-P1, 9.9.x before 9.9.1-P1, and 9.4-ESV and 9.6-ESV before 9.6-ESV-R7-P1 does not properly handle resource records with a zero-length RDATA section, which allows remote DNS servers to cause a denial of service (daemon crash or data corruption) or obtain sensitive information from process memory via a crafted record. Scope:
debian
CVE-2016-2848P3HIGHCVSS 7.5fixed in bind9 1:9.9.3.dfsg.P2-1 (bookworm)2016
CVE-2016-2848 [HIGH] CVE-2016-2848: bind9 - ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attacke... ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record. Scope: local bookworm: resolved (fixed in 1:9.9.3.dfsg.P2-1) bullseye: resolved (fixed in 1:9.9.3.dfsg.P2-1) forky: resolved (fixed in 1:9.9.3.dfsg.P2-1) sid: resolved (f
debian
Debian Bind9 vulnerabilities | cvebase