Debian Bind9 vulnerabilities
127 known vulnerabilities affecting debian/bind9.
Total CVEs
127
CISA KEV
0
Public exploits
7
Exploited in wild
4
Severity breakdown
HIGH73MEDIUM35LOW19
Vulnerabilities
Page 3 of 7
CVE-2016-9147P3HIGHCVSS 7.5fixed in bind9 1:9.10.3.dfsg.P4-11 (bookworm)2016
CVE-2016-9147 [HIGH] CVE-2016-9147: bind9 - named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote att...
named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets.
Scope: local
bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-11)
bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-11)
forky: resolved (fixed in 1:9.1
debian
CVE-2018-5738P3MEDIUMCVSS 5.3fixed in bind9 1:9.11.3+dfsg-2 (bookworm)2018
CVE-2018-5738 [MEDIUM] CVE-2018-5738: bind9 - Change #4777 (introduced in October 2017) introduced an unforeseen issue in rele...
Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one of the following
debian
CVE-2026-1519P3HIGHCVSS 7.5fixed in bind9 1:9.18.47-1~deb12u1 (bookworm)2026
CVE-2026-1519 [HIGH] CVE-2026-1519: bind9 - If a BIND resolver is performing DNSSEC validation and encounters a maliciously ...
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issu
debian
CVE-2017-3143P3HIGHCVSS 7.5fixed in bind9 1:9.10.3.dfsg.P4-12.4 (bookworm)2017
CVE-2017-3143 [HIGH] CVE-2017-3143: bind9 - An attacker who is able to send and receive messages to an authoritative DNS ser...
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S
debian
CVE-2023-3341P3HIGHCVSS 7.5fixed in bind9 1:9.18.19-1~deb12u1 (bookworm)2023
CVE-2023-3341 [HIGH] CVE-2023-3341: bind9 - The code that processes control channel messages sent to `named` calls certain f...
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control c
debian
CVE-2016-6170P3LOWCVSS 6.5fixed in bind9 1:9.10.6+dfsg-1 (bookworm)2016
CVE-2016-6170 [MEDIUM] CVE-2016-6170: bind9 - ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1...
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote authenticated users to cause a denial of service (p
debian
CVE-2020-8623P3HIGHCVSS 7.5fixed in bind9 1:9.16.6-1 (bookworm)2020
CVE-2020-8623 [HIGH] CVE-2020-8623: bind9 - In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10...
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signing one or more zo
debian
CVE-2007-2926P4MEDIUMCVSS 4.3PoCfixed in bind9 1:9.4.1-P1-1 (bookworm)2007
CVE-2007-2926 [MEDIUM] CVE-2007-2926: bind9 - ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation...
ISC BIND 9 through 9.5.0a5 uses a weak random number generator during generation of DNS query ids when answering resolver questions or sending NOTIFY messages to slave name servers, which makes it easier for remote attackers to guess the next query id and perform DNS cache poisoning.
Scope: local
bookworm: resolved (fixed in 1:9.4.1-P1-1)
bullseye: resolved (fixed in
debian
CVE-2024-0760P3HIGHCVSS 7.5fixed in bind9 1:9.18.28-1~deb12u1 (bookworm)2024
CVE-2024-0760 [HIGH] CVE-2024-0760: bind9 - A malicious client can send many DNS messages over TCP, potentially causing the ...
A malicious client can send many DNS messages over TCP, potentially causing the server to become unstable while the attack is in progress. The server may recover after the attack ceases. Use of ACLs will not mitigate the attack. This issue affects BIND 9 versions 9.18.1 through 9.18.27, 9.19.0 through 9.19.24, and 9.18.11-S1 through 9.18.27-S1.
Scope: local
bookworm: re
debian
CVE-2018-5743P3HIGHCVSS 7.5fixed in bind9 1:9.11.5.P4+dfsg-4 (bookworm)2018
CVE-2018-5743 [HIGH] CVE-2018-5743: bind9 - By design, BIND is intended to limit the number of TCP clients that can be conne...
By design, BIND is intended to limit the number of TCP clients that can be connected at any given time. The number of allowed connections is a tunable parameter which, if unset, defaults to a conservative value for most servers. Unfortunately, the code which was intended to limit the number of simultaneous connections contained an error which could be exploited to grow
debian
CVE-2023-2828P3HIGHCVSS 7.5fixed in bind9 1:9.18.16-1~deb12u1 (bookworm)2023
CVE-2023-2828 [HIGH] CVE-2023-2828: bind9 - Every `named` instance configured to run as a recursive resolver maintains a cac...
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of the total amount of memory available on the host. Whe
debian
CVE-2017-3137P3HIGHCVSS 7.5vDebian BIND9 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.12019-01-16
CVE-2017-3137 [HIGH] CWE-617 CVE-2017-3137: Mistaken assumptions about the ordering of records in the answer section of a response containing CN
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.4-P6, 9.10.5b1->9.10.5rc
nvddebian
CVE-2024-1975P3HIGHCVSS 7.5fixed in bind9 1:9.18.28-1~deb12u1 (bookworm)2024
CVE-2024-1975 [HIGH] CVE-2024-1975: bind9 - If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSE...
If a server hosts a zone containing a "KEY" Resource Record, or a resolver DNSSEC-validates a "KEY" Resource Record from a DNSSEC-signed domain in cache, a client can exhaust resolver CPU resources by sending a stream of SIG(0) signed requests. This issue affects BIND 9 versions 9.0.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.2
debian
CVE-2015-8000P3MEDIUMCVSS 5.0fixed in bind9 1:9.9.5.dfsg-12.1 (bookworm)2015
CVE-2015-8000 [MEDIUM] CVE-2015-8000: bind9 - db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows...
db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a malformed class attribute.
Scope: local
bookworm: resolved (fixed in 1:9.9.5.dfsg-12.1)
bullseye: resolved (fixed in 1:9.9.5.dfsg-12.1)
forky: resolved (fixed in 1:9.9.5.dfsg-12.1)
sid: resolve
debian
CVE-2024-1737P3HIGHCVSS 7.5fixed in bind9 1:9.18.28-1~deb12u1 (bookworm)2024
CVE-2024-1737 [HIGH] CVE-2024-1737: bind9 - Resolver caches and authoritative zone databases that hold significant numbers o...
Resolver caches and authoritative zone databases that hold significant numbers of RRs for the same hostname (of any RTYPE) can suffer from degraded performance as content is being added or updated, and also when handling client queries for this name. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through
debian
CVE-2024-4076P3HIGHCVSS 7.5fixed in bind9 1:9.18.28-1~deb12u1 (bookworm)2024
CVE-2024-4076 [HIGH] CVE-2024-4076: bind9 - Client queries that trigger serving stale data and that also require lookups in ...
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.
Scope: local
bookworm
debian
CVE-2026-3104P3LOWCVSS 7.5fixed in bind9 1:9.20.21-1 (forky)2026
CVE-2026-3104 [HIGH] CVE-2026-3104: bind9 - A specially crafted domain can be used to cause a memory leak in a BIND resolver...
A specially crafted domain can be used to cause a memory leak in a BIND resolver simply by querying this domain. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.
Scope: local
bookworm: resolved
bullseye: resolved
debian
CVE-2018-5744P3HIGHCVSS 7.5fixed in bind9 1:9.11.5.P4+dfsg-1 (bookworm)2018
CVE-2018-5744 [HIGH] CVE-2018-5744: bind9 - A failure to free memory can occur when processing messages having a specific co...
A failure to free memory can occur when processing messages having a specific combination of EDNS options. Versions affected are: BIND 9.10.7 -> 9.10.8-P1, 9.11.3 -> 9.11.5-P1, 9.12.0 -> 9.12.3-P1, and versions 9.10.7-S1 -> 9.11.5-S3 of BIND 9 Supported Preview Edition. Versions 9.13.0 -> 9.13.6 of the 9.13 development branch are also affected.
Scope: local
bookworm: re
debian
CVE-2023-2911P3HIGHCVSS 7.5fixed in bind9 1:9.18.16-1~deb12u1 (bookworm)2023
CVE-2023-2911 [HIGH] CVE-2023-2911: bind9 - If the `recursive-clients` quota is reached on a BIND 9 resolver configured with...
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33 through 9.16.41, 9.18.7 through 9.18.15, 9.16.33-S1 thro
debian
CVE-2023-4236P3HIGHCVSS 7.5fixed in bind9 1:9.18.19-1~deb12u1 (bookworm)2023
CVE-2023-4236 [HIGH] CVE-2023-4236: bind9 - A flaw in the networking code handling DNS-over-TLS queries may cause `named` to...
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.
Scope: local
bookworm: resolved (fixe
debian