Debian Bind9 vulnerabilities
127 known vulnerabilities affecting debian/bind9.
Total CVEs
127
CISA KEV
0
Public exploits
7
Exploited in wild
4
Severity breakdown
HIGH73MEDIUM35LOW19
Vulnerabilities
Page 5 of 7
CVE-2015-1349P3LOWCVSS 5.4fixed in bind9 1:9.9.5.dfsg-9 (bookworm)2015
CVE-2015-1349 [MEDIUM] CVE-2015-1349: bind9 - named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P...
named in ISC BIND 9.7.0 through 9.9.6 before 9.9.6-P2 and 9.10.x before 9.10.1-P2, when DNSSEC validation and the managed-keys feature are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit, or daemon crash) by triggering an incorrect trust-anchor management scenario in which no key is ready for use.
Scope: local
bookworm:
debian
CVE-2022-38177P3HIGHCVSS 7.5fixed in bind9 1:9.17.20-1 (bookworm)2022
CVE-2022-38177 [HIGH] CVE-2022-38177: bind9 - By spoofing the target resolver with responses that have a malformed ECDSA signa...
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Scope: local
bookworm: resolved (fixed in 1:9.17.20-1)
bullseye: resolved (fixed in 1:9.16.33-1~deb11u1)
forky: resolved (fixed in 1
debian
CVE-2009-0025P3LOWCVSS 5.8fixed in bind9 1:9.5.1.dfsg.P1-1 (bookworm)2009
CVE-2009-0025 [MEDIUM] CVE-2009-0025: bind9 - BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return ...
BIND 9.6.0, 9.5.1, 9.5.0, 9.4.3, and earlier does not properly check the return value from the OpenSSL DSA_verify function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077.
Scope: local
bookworm: resolved (fixed in 1:9.5.1.dfsg.P1-1)
bullseye: resolved (fixed in 1:9
debian
CVE-2022-38178P3HIGHCVSS 7.5fixed in bind9 1:9.18.7-1 (bookworm)2022
CVE-2022-38178 [HIGH] CVE-2022-38178: bind9 - By spoofing the target resolver with responses that have a malformed EdDSA signa...
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
Scope: local
bookworm: resolved (fixed in 1:9.18.7-1)
bullseye: resolved (fixed in 1:9.16.33-1~deb11u1)
forky: resolved (fixed in 1:
debian
CVE-2022-0635P3HIGHCVSS 7.5fixed in bind9 1:9.18.1-1 (bookworm)2022
CVE-2022-0635 [HIGH] CVE-2022-0635: bind9 - Versions affected: BIND 9.18.0 When a vulnerable version of named receives a ser...
Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.
Scope: local
bookworm: resolved (fixed in 1:9.18.1-1)
bullseye: resolved
forky: resolved (fixed in 1:9.18.1-1)
sid: resolved (fixed in 1:9.18.1-1)
trixie: resolved (fixed in 1:9.18.1-1)
debian
CVE-2018-5741P3LOWCVSS 6.5fixed in bind9 1:9.11.5+dfsg-1 (bookworm)2018
CVE-2018-5741 [MEDIUM] CVE-2018-5741: bind9 - To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to u...
To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update request. Unfortunately, some rule types were not initially documented,
debian
CVE-2021-25219P3MEDIUMCVSS 5.3fixed in bind9 1:9.17.19-1 (bookworm)2021
CVE-2021-25219 [MEDIUM] CVE-2021-25219: bind9 - In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1...
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way
debian
CVE-2018-5735P3HIGHCVSS 7.5fixed in bind9 1:9.9.3.dfsg.P2-1 (bookworm)2018
CVE-2018-5735 [HIGH] CVE-2018-5735: bind9 - The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in v...
The Debian backport of the fix for CVE-2017-3137 leads to assertion failure in validator.c:1858; Affects Debian versions 9.9.5.dfsg-9+deb8u15; 9.9.5.dfsg-9+deb8u18; 9.10.3.dfsg.P4-12.3+deb9u5; 9.11.5.P4+dfsg-5.1 No ISC releases are affected. Other packages from other distributions who did similar backports for the fix for 2017-3137 may also be affected.
Scope: local
boo
debian
CVE-2007-0493P3MEDIUMCVSS 7.8fixed in bind9 1:9.3.4-2 (bookworm)2007
CVE-2007-0493 [HIGH] CVE-2007-0493: bind9 - Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a...
Use-after-free vulnerability in ISC BIND 9.3.0 up to 9.3.3, 9.4.0a1 up to 9.4.0a6, 9.4.0b1 up to 9.4.0b4, 9.4.0rc1, and 9.5.0a1 (Bind Forum only) allows remote attackers to cause a denial of service (named daemon crash) via unspecified vectors that cause named to "dereference a freed fetch context."
Scope: local
bookworm: resolved (fixed in 1:9.3.4-2)
bullseye: resolved
debian
CVE-2017-3138P3MEDIUMCVSS 6.5fixed in bind9 1:9.10.3.dfsg.P4-12.3 (bookworm)2017
CVE-2017-3138 [MEDIUM] CVE-2017-3138: bind9 - named contains a feature which allows operators to issue commands to a running s...
named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure if they are sent
debian
CVE-2021-25220P3MEDIUMCVSS 6.8fixed in bind9 1:9.18.1-1 (bookworm)2021
CVE-2021-25220 [MEDIUM] CVE-2021-25220: bind9 - BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview...
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records
debian
CVE-2022-0667P3HIGHCVSS 7.5fixed in bind9 1:9.18.1-1 (bookworm)2022
CVE-2022-0667 [HIGH] CVE-2022-0667: bind9 - When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
When the vulnerability is triggered the BIND process will exit. BIND 9.18.0
Scope: local
bookworm: resolved (fixed in 1:9.18.1-1)
bullseye: resolved
forky: resolved (fixed in 1:9.18.1-1)
sid: resolved (fixed in 1:9.18.1-1)
trixie: resolved (fixed in 1:9.18.1-1)
debian
CVE-2011-0414P4HIGHCVSS 7.1fixed in bind9 1:9.7.3.dfsg-1 (bookworm)2011
CVE-2011-0414 [HIGH] CVE-2011-0414: bind9 - ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, all...
ISC BIND 9.7.1 through 9.7.2-P3, when configured as an authoritative server, allows remote attackers to cause a denial of service (deadlock and daemon hang) by sending a query at the time of (1) an IXFR transfer or (2) a DDNS update.
Scope: local
bookworm: resolved (fixed in 1:9.7.3.dfsg-1)
bullseye: resolved (fixed in 1:9.7.3.dfsg-1)
forky: resolved (fixed in 1:9.7.3.d
debian
CVE-2022-2881P3MEDIUMCVSS 5.5fixed in bind9 1:9.18.7-1 (bookworm)2022
CVE-2022-2881 [MEDIUM] CVE-2022-2881: bind9 - The underlying bug might cause read past end of the buffer and either read memor...
The underlying bug might cause read past end of the buffer and either read memory it should not read, or crash the process.
Scope: local
bookworm: resolved (fixed in 1:9.18.7-1)
bullseye: open
forky: resolved (fixed in 1:9.18.7-1)
sid: resolved (fixed in 1:9.18.7-1)
trixie: resolved (fixed in 1:9.18.7-1)
debian
CVE-2006-4095P4MEDIUMCVSS 7.5fixed in bind9 1:9.3.2-P1-1 (bookworm)2006
CVE-2006-4095 [HIGH] CVE-2006-4095: bind9 - BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause ...
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
Scope: local
bookworm: resolved (fixed in 1:9.3.2-P1-1)
bullseye: resolved (fixed in 1:9.3.2-P1-1)
forky: resolved (fixed in 1:9.3.2-P1-1)
sid: resolved (fixed in 1:9.3.2-
debian
CVE-2010-3614P3MEDIUMCVSS 6.4fixed in bind9 1:9.7.2.dfsg.P3-1 (bookworm)2010
CVE-2010-3614 [MEDIUM] CVE-2010-3614: bind9 - named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4...
named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.
Scope: local
bookworm: resolved (fix
debian
CVE-2012-5689P4HIGHCVSS 7.1fixed in bind9 1:9.8.4.dfsg.P1-6+nmu1 (bookworm)2012
CVE-2012-5689 [HIGH] CVE-2012-5689: bind9 - ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configura...
ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.
Scope: local
bookworm: resolved (fixed in 1:9.8.4.dfsg.P1-6+nmu1)
bullseye: resolv
debian
CVE-2026-3591P4LOWCVSS 5.4fixed in bind9 1:9.20.21-1 (forky)2026
CVE-2026-3591 [MEDIUM] CVE-2026-3591: bind9 - A use-after-return vulnerability exists in the `named` server when handling DNS ...
A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This i
debian
CVE-2011-2464P4HIGHCVSS 5.0fixed in bind9 1:9.8.1.dfsg-1 (bookworm)2011
CVE-2011-2464 [MEDIUM] CVE-2011-2464: bind9 - Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before...
Unspecified vulnerability in ISC BIND 9 9.6.x before 9.6-ESV-R4-P3, 9.7.x before 9.7.3-P3, and 9.8.x before 9.8.0-P4 allows remote attackers to cause a denial of service (named daemon crash) via a crafted UPDATE request.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg-1)
bullseye: resolved (fixed in 1:9.8.1.dfsg-1)
forky: resolved (fixed in 1:9.8.1.dfsg-1)
sid:
debian
CVE-2011-1910P4HIGHCVSS 5.0fixed in bind9 1:9.8.1.dfsg-1 (bookworm)2011
CVE-2011-1910 [MEDIUM] CVE-2011-1910: bind9 - Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2...
Off-by-one error in named in ISC BIND 9.x before 9.7.3-P1, 9.8.x before 9.8.0-P2, 9.4-ESV before 9.4-ESV-R4-P1, and 9.6-ESV before 9.6-ESV-R4-P1 allows remote DNS servers to cause a denial of service (assertion failure and daemon exit) via a negative response containing large RRSIG RRsets.
Scope: local
bookworm: resolved (fixed in 1:9.8.1.dfsg-1)
bullseye: resolved (f
debian