cbcvebase.

Isc Bind 9 vulnerabilities

68 known vulnerabilities affecting isc/bind_9.

Total CVEs
68
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH48MEDIUM18LOW1

Vulnerabilities

Page 1 of 4
CVE-2018-5740P2HIGHCVSS 7.5vBIND 9 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.22019-01-16
CVE-2018-5740 [HIGH] CWE-617 CVE-2018-5740: "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect e "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND
nvd
CVE-2022-3736P3HIGHCVSS 7.5≥ 9.16.12, ≤ 9.16.36≥ 9.18.0, ≤ 9.18.10+2 more2023-01-26
CVE-2022-3736 [HIGH] CWE-20 CVE-2022-3736: BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-clien BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
nvd
CVE-2017-3141P3HIGHCVSS 7.8PoCv9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S12019-01-16
CVE-2017-3141 [HIGH] CWE-428 CVE-2017-3141: The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalation if the host file system permissions allow this. Affects BIND 9.2.6-P2->9.2.9, 9.3.2-P1->9.3.6, 9.4.0->9.8.8, 9.9.0->9.9.10, 9.10.0->9.10.5, 9.11.0->9.11.1, 9.9.3-S1->9.9.10-S1, 9.10.5-S1.
nvd
CVE-2026-3593P2CRITICALCVSS 9.8≥ 9.20.0, ≤ 9.20.22≥ 9.21.0, ≤ 9.21.21+1 more2026-05-20
CVE-2026-3593 [CRITICAL] CWE-416 CVE-2026-3593: A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects B A use-after-free vulnerability exists within the DNS-over-HTTPS implementation. This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1. BIND 9 versions 9.18.0 through 9.18.48 and 9.18.11-S1 through 9.18.48-S1 are NOT affected.
nvd
CVE-2024-11187P3HIGHCVSS 7.5≥ 9.11.0, ≤ 9.11.37≥ 9.16.0, ≤ 9.16.50+6 more2025-01-29
CVE-2024-11187 [HIGH] CWE-405 CVE-2024-11187: It is possible to construct a zone such that some queries to it will generate responses containing n It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been d
nvd
CVE-2017-3145P3HIGHCVSS 7.5v9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc12019-01-16
CVE-2017-3145 [HIGH] CWE-416 CVE-2017-3145: BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in s BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
nvd
CVE-2024-12705P3HIGHCVSS 7.5≥ 9.18.0, ≤ 9.18.32≥ 9.20.0, ≤ 9.20.4+2 more2025-01-29
CVE-2024-12705 [HIGH] CWE-770 CVE-2024-12705: Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it wit Clients using DNS-over-HTTPS (DoH) can exhaust a DNS resolver's CPU and/or memory by flooding it with crafted valid or invalid HTTP/2 traffic. This issue affects BIND 9 versions 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, and 9.18.11-S1 through 9.18.32-S1.
nvd
CVE-2022-3924P3HIGHCVSS 7.5≥ 9.16.12, ≤ 9.16.36≥ 9.18.0, ≤ 9.18.10+2 more2023-01-26
CVE-2022-3924 [HIGH] CWE-617 CVE-2022-3924: This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the opt This issue can affect BIND 9 resolvers with `stale-answer-enable yes;` that also make use of the option `stale-answer-client-timeout`, configured with a value greater than zero. If the resolver receives many queries that require recursion, there will be a corresponding increase in the number of clients that are waiting for recursion to complete. If the
nvd
CVE-2022-3488P3HIGHCVSS 7.5≥ 9.11.4-S1, ≤ 9.11.37-S1≥ 9.16.8-S1, ≤ 9.16.36-S12023-01-26
CVE-2022-3488 [HIGH] CWE-617 CVE-2022-3488: Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure. 'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue af
nvd
CVE-2025-8677P3HIGHCVSS 7.5≥ 9.18.0, ≤ 9.18.39≥ 9.20.0, ≤ 9.20.13+3 more2025-10-22
CVE-2025-8677 [HIGH] CWE-405 CVE-2025-8677: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
nvd
CVE-2025-13878P3HIGHCVSS 7.5≥ 9.18.40, ≤ 9.18.43≥ 9.20.13, ≤ 9.20.17+3 more2026-01-21
CVE-2025-13878 [HIGH] CWE-617 CVE-2025-13878: Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 v Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.
nvd
CVE-2025-40778P3HIGHCVSS 8.6≥ 9.11.0, ≤ 9.16.50≥ 9.18.0, ≤ 9.18.39+5 more2025-10-22
CVE-2025-40778 [HIGH] CWE-349 CVE-2025-40778: Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an at Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 th
nvd
CVE-2025-40775P3HIGHCVSS 7.5≥ 9.20.0, ≤ 9.20.8≥ 9.21.0, ≤ 9.21.72025-05-21
CVE-2025-40775 [HIGH] CWE-232 CVE-2025-40775: When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.
nvd
CVE-2022-3094P3HIGHCVSS 7.5≥ 9.16.0, ≤ 9.16.36≥ 9.18.0, ≤ 9.18.10+2 more2023-01-26
CVE-2022-3094 [HIGH] CWE-416 CVE-2022-3094: Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, Sending a flood of dynamic DNS updates may cause `named` to allocate large amounts of memory. This, in turn, may cause `named` to exit due to a lack of free memory. We are not aware of any cases where this has been exploited. Memory is allocated prior to the checking of access permissions (ACLs) and is retained during the processing of a dynamic update
nvd
CVE-2025-40780P3HIGHCVSS 8.6≥ 9.16.0, ≤ 9.16.50≥ 9.18.0, ≤ 9.18.39+5 more2025-10-22
CVE-2025-40780 [HIGH] CWE-341 CVE-2025-40780: In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is us In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S
nvd
CVE-2026-5946P3HIGHCVSS 7.5≥ 9.11.0, ≤ 9.16.50≥ 9.18.0, ≤ 9.18.48+5 more2026-05-20
CVE-2026-5946 [HIGH] CWE-20 CVE-2026-5946: Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS i Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change
nvd
CVE-2018-5738P3HIGHCVSS 7.5v9.9.12, 9.10.7, 9.11.3, 9.12.0->9.12.1-P2, the development release 9.13.0, and also releases 9.9.12-S1, 9.10.7-S1, 9.11.3-S1, and 9.11.3-S2 from BIND 9 Supported Preview Edition.2019-01-16
CVE-2018-5738 [HIGH] CWE-200 CVE-2018-5738: Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issu Change #4777 (introduced in October 2017) introduced an unforeseen issue in releases which were issued after that date, affecting which clients are permitted to make recursive queries to a BIND nameserver. The intended (and documented) behavior is that if an operator has not specified a value for the "allow-recursion" setting, it SHOULD default to one o
nvd
CVE-2025-40776P3HIGHCVSS 8.6≥ 9.11.3-S1, ≤ 9.16.50-S1≥ 9.18.11-S1, ≤ 9.18.37-S1+1 more2025-07-16
CVE-2025-40776 [HIGH] CWE-349 CVE-2025-40776: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulner A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
nvd
CVE-2026-1519P3HIGHCVSS 7.5≥ 9.11.0, ≤ 9.16.50≥ 9.18.0, ≤ 9.18.46+5 more2026-03-25
CVE-2026-1519 [HIGH] CWE-606 CVE-2026-1519: If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the re If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-qu
nvd
CVE-2026-13321P3HIGHCVSS 8.6≥ 9.11.0, ≤ 9.18.50≥ 9.20.0, ≤ 9.20.24+3 more2026-07-22
CVE-2026-13321 [HIGH] CWE-346 CVE-2026-13321: The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outs The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
nvd
Isc Bind 9 vulnerabilities | cvebase