cbcvebase.

Debian Bind9 vulnerabilities

127 known vulnerabilities affecting debian/bind9.

Total CVEs
127
CISA KEV
0
Public exploits
7
Exploited in wild
4
Severity breakdown
HIGH73MEDIUM35LOW19

Vulnerabilities

Page 4 of 7
CVE-2023-4408P3HIGHCVSS 7.5fixed in bind9 1:9.18.24-1 (bookworm)2023
CVE-2023-4408 [HIGH] CVE-2023-4408: bind9 - The DNS message parsing code in `named` includes a section whose computational c... The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This issue affects BIN
debian
CVE-2008-0122P3LOWCVSS 10.0fixed in glibc 2.2-1 (bookworm)2008
CVE-2008-0122 [CRITICAL] CVE-2008-0122: bind9 - Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and e... Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption. Scope: local bookworm: resolved bullseye: resolved forky: resolved
debian
CVE-2022-1183P3HIGHCVSS 7.5fixed in bind9 1:9.18.3-1 (bookworm)2022
CVE-2022-1183 [HIGH] CVE-2022-1183: bind9 - On vulnerable configurations, the named daemon may, in some circumstances, termi... On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 ->
debian
CVE-2017-3135P3HIGHCVSS 7.5fixed in bind9 1:9.10.3.dfsg.P4-12 (bookworm)2017
CVE-2017-3135 [HIGH] CVE-2017-3135: bind9 - Under some conditions when using both DNS64 and RPZ to rewrite query responses, ... Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b1. Scope: local b
debian
CVE-2020-8620P3HIGHCVSS 7.5fixed in bind9 1:9.16.6-1 (bookworm)2020
CVE-2020-8620 [HIGH] CVE-2020-8620: bind9 - In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP ... In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit. Scope: local bookworm: resolved (fixed in 1:9.16.6-1) bullseye: resolved (fixed in 1:9.16.6-1) forky: resolved (fixed in 1:9.16.6-1) sid: resolved (fixed
debian
CVE-2023-5517P3HIGHCVSS 7.5fixed in bind9 1:9.18.24-1 (bookworm)2023
CVE-2023-5517 [HIGH] CVE-2023-5517: bind9 - A flaw in query-handling code can cause `named` to exit prematurely with an asse... A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect ;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.
debian
CVE-2025-40777P3HIGHCVSS 7.5fixed in bind9 1:9.20.11-1 (forky)2025
CVE-2025-40777 [HIGH] CVE-2025-40777: bind9 - If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and... If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion f
debian
CVE-2020-8621P3HIGHCVSS 7.5fixed in bind9 1:9.16.6-1 (bookworm)2020
CVE-2020-8621 [HIGH] CVE-2020-8621: bind9 - In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both ... In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected. Scope: local bookworm: resolved (fixed in 1:9.16.6-1) bullseye: resolved (fixed in 1:9.16
debian
CVE-2023-5679P3HIGHCVSS 7.5fixed in bind9 1:9.18.24-1 (bookworm)2023
CVE-2023-5679 [HIGH] CVE-2023-5679: bind9 - A bad interaction between DNS64 and serve-stale may cause `named` to crash with ... A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1. Scope: local bookworm: reso
debian
CVE-2019-6477P3HIGHCVSS 7.5fixed in bind9 1:9.11.14+dfsg-1 (bookworm)2019
CVE-2019-6477 [HIGH] CVE-2019-6477: bind9 - With pipelining enabled each incoming query on a TCP connection requires a simil... With pipelining enabled each incoming query on a TCP connection requires a similar resource allocation to a query received via UDP or via TCP without pipelining enabled. A client using a TCP-pipelined connection to a server could consume more resources than the server has been provisioned to handle. When a TCP connection with a large number of pipelined queries is close
debian
CVE-2020-8622P3MEDIUMCVSS 6.5fixed in bind9 1:9.16.6-1 (bookworm)2020
CVE-2020-8622 [MEDIUM] CVE-2020-8622: bind9 - In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3... In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alt
debian
CVE-2022-2906P3HIGHCVSS 7.5fixed in bind9 1:9.18.7-1 (bookworm)2022
CVE-2022-2906 [HIGH] CVE-2022-2906: bind9 - An attacker can leverage this flaw to gradually erode available memory to the po... An attacker can leverage this flaw to gradually erode available memory to the point where named crashes for lack of resources. Upon restart the attacker would have to begin again, but nevertheless there is the potential to deny service. Scope: local bookworm: resolved (fixed in 1:9.18.7-1) bullseye: resolved forky: resolved (fixed in 1:9.18.7-1) sid: resolved (fixed in
debian
CVE-2022-3080P3HIGHCVSS 7.5fixed in bind9 1:9.18.7-1 (bookworm)2022
CVE-2022-3080 [HIGH] CVE-2022-3080: bind9 - By sending specific queries to the resolver, an attacker can cause named to cras... By sending specific queries to the resolver, an attacker can cause named to crash. Scope: local bookworm: resolved (fixed in 1:9.18.7-1) bullseye: resolved (fixed in 1:9.16.33-1~deb11u1) forky: resolved (fixed in 1:9.18.7-1) sid: resolved (fixed in 1:9.18.7-1) trixie: resolved (fixed in 1:9.18.7-1)
debian
CVE-2015-8704P3MEDIUMCVSS 6.5fixed in bind9 1:9.10.3.dfsg.P4-6 (bookworm)2015
CVE-2015-8704 [MEDIUM] CVE-2015-8704: bind9 - apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 all... apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed Address Prefix List (APL) record. Scope: local bookworm: resolved (fixed in 1:9.10.3.dfsg.P4-6) bullseye: resolved (fixed in 1:9.10.3.dfsg.P4-6) forky: resolved (fixed in
debian
CVE-2026-3119P3LOWCVSS 6.5fixed in bind9 1:9.20.21-1 (forky)2026
CVE-2026-3119 [MEDIUM] CVE-2026-3119: bind9 - Under certain conditions, `named` may crash when processing a correctly signed q... Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.
debian
CVE-2021-25214P3MEDIUMCVSS 6.5fixed in bind9 1:9.16.15-1 (bookworm)2021
CVE-2021-25214 [MEDIUM] CVE-2021-25214: bind9 - In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9... In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process wi
debian
CVE-2017-3136P3MEDIUMCVSS 5.9fixed in bind9 1:9.10.3.dfsg.P4-12.3 (bookworm)2017
CVE-2017-3136 [MEDIUM] CVE-2017-3136: bind9 - A query with a specific set of characteristics could cause a server using DNS64 ... A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6, 9.9.10b1->9.9.10
debian
CVE-2023-6516P3HIGHCVSS 7.5fixed in bind9 1:9.17.19-1 (bookworm)2023
CVE-2023-6516 [HIGH] CVE-2023-6516: bind9 - To keep its cache database efficient, `named` running as a recursive resolver oc... To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the resolver is continu
debian
CVE-2010-0382P3LOWCVSS 2.6fixed in bind9 1:9.7.0.dfsg-1 (bookworm)2010
CVE-2010-0382 [LOW] CVE-2010-0382: bind9 - ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 befo... ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression dur
debian
CVE-2012-5688P3HIGHCVSS 7.8fixed in bind9 1:9.8.4.dfsg.P1-1 (bookworm)2012
CVE-2012-5688 [HIGH] CVE-2012-5688: bind9 - ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled,... ISC BIND 9.8.x before 9.8.4-P1 and 9.9.x before 9.9.2-P1, when DNS64 is enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query. Scope: local bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-1) bullseye: resolved (fixed in 1:9.8.4.dfsg.P1-1) forky: resolved (fixed in 1:9.8.4.dfsg.P1-1) sid: resolved (fixed in 1:9
debian
Debian Bind9 vulnerabilities | cvebase