cbcvebase.

Isc Bind 9 vulnerabilities

68 known vulnerabilities affecting isc/bind_9.

Total CVEs
68
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH48MEDIUM18LOW1

Vulnerabilities

Page 3 of 4
CVE-2023-4236P3HIGHCVSS 7.5≥ 9.18.0, ≤ 9.18.18≥ 9.18.11-S1, ≤ 9.18.18-S12023-09-20
CVE-2023-4236 [HIGH] CWE-617 CVE-2023-4236: A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpecte A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.
nvd
CVE-2023-4408P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.16.45≥ 9.18.0, ≤ 9.18.21+4 more2024-02-13
CVE-2023-4408 [HIGH] CWE-407 CVE-2023-4408: The DNS message parsing code in `named` includes a section whose computational complexity is overly The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw. This issue affects both authoritative servers and recursive resolvers. This i
nvd
CVE-2017-3135P3MEDIUMCVSS 5.9vBIND 9 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.1b12019-01-16
CVE-2017-3135 [MEDIUM] CWE-476 CVE-2017-3135: Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5, 9.10.5b1, 9.11.0 -> 9.11.0-P2, 9.11.
nvd
CVE-2026-13204P3HIGHCVSS 7.5≥ 9.11.0, ≤ 9.18.50≥ 9.20.0, ≤ 9.20.24+3 more2026-07-22
CVE-2026-13204 [HIGH] CWE-617 CVE-2026-13204: If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there e If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.5
nvd
CVE-2026-12617P3HIGHCVSS 7.5≥ 9.18.0, ≤ 9.18.50≥ 9.20.0, ≤ 9.20.24+2 more2026-07-22
CVE-2026-12617 [HIGH] CWE-617 CVE-2026-12617: The issue is unexpected program termination based on ordering and/or specific content in responses t The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds neg
nvd
CVE-2023-5517P3HIGHCVSS 7.5≥ 9.12.0, ≤ 9.16.45≥ 9.18.0, ≤ 9.18.21+3 more2024-02-13
CVE-2023-5517 [HIGH] CWE-617 CVE-2023-5517: A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect ;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This issue affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.1
nvd
CVE-2025-40777P3HIGHCVSS 7.5≥ 9.20.0, ≤ 9.20.10≥ 9.21.0, ≤ 9.21.9+1 more2025-07-16
CVE-2025-40777 [HIGH] CWE-617 CVE-2025-40777: If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer- If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort wi
nvd
CVE-2023-5679P3HIGHCVSS 7.5≥ 9.16.12, ≤ 9.16.45≥ 9.18.0, ≤ 9.18.21+3 more2024-02-13
CVE-2023-5679 [HIGH] CWE-617 CVE-2023-5679: A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
nvd
CVE-2023-2829P3HIGHCVSS 7.5≥ 9.16.8-S1, ≤ 9.16.41-S1≥ 9.18.11-S1, ≤ 9.18.15-S12023-06-21
CVE-2023-2829 [HIGH] CVE-2023-2829: A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive U A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and 9.18.11-S1 through 9.18.15-S1.
nvd
CVE-2026-3119P3MEDIUMCVSS 6.5≥ 9.20.0, ≤ 9.20.20≥ 9.21.0, ≤ 9.21.19+1 more2026-03-25
CVE-2026-3119 [MEDIUM] CWE-617 CVE-2026-3119: Under certain conditions, `named` may crash when processing a correctly signed query containing a TK Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.2
nvd
CVE-2017-3136P3MEDIUMCVSS 5.9v9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6, 9.9.10b1->9.9.10rc1, 9.10.0 -> 9.10.4-P6, 9.10.5b1->9.10.5rc1, 9.11.0 -> 9.11.0-P3, 9.11.1b1->9.11.1rc1, 9.9.3-S1 -> 9.9.9-S82019-01-16
CVE-2017-3136 [MEDIUM] CWE-617 CVE-2017-3136: A query with a specific set of characteristics could cause a server using DNS64 to encounter an asse A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND 9.8.0 -> 9.8.8-P1, 9.9.0 -> 9.9.9-P6,
nvd
CVE-2023-6516P3HIGHCVSS 7.5≥ 9.16.0, ≤ 9.16.45≥ 9.16.8-S1, ≤ 9.16.45-S12024-02-13
CVE-2023-6516 [HIGH] CWE-770 CVE-2023-6516: To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later processing. It was discovered that if the res
nvd
CVE-2019-6476P3HIGHCVSS 7.5v9.14.0 up to 9.14.6v9.15.0 up to 9.15.42019-10-17
CVE-2019-6476 [HIGH] CWE-617 CVE-2019-6476: A defect in code added to support QNAME minimization can cause named to exit with an assertion failu A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15.4.
nvd
CVE-2018-5741P3MEDIUMCVSS 6.5vBIND 9 Versions prior to BIND 9.11.5 and BIND 9.12.32019-01-16
CVE-2018-5741 [MEDIUM] CWE-863 CVE-2018-5741: To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a z To provide fine-grained controls over the ability to use Dynamic DNS (DDNS) to update records in a zone, BIND 9 provides a feature called update-policy. Various rules can be configured to limit the types of updates that can be performed by a client, depending on the key used when sending the update request. Unfortunately, some rule types were not init
nvd
CVE-2026-10723P3MEDIUMCVSS 6.8≥ 9.18.0, ≤ 9.18.50≥ 9.20.0, ≤ 9.20.24+3 more2026-07-22
CVE-2026-10723 [MEDIUM] CWE-347 CVE-2026-10723: BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
nvd
CVE-2016-9778P3MEDIUMCVSS 5.9vBIND 9 9.9.8-S1 -> 9.9.8-S3, 9.9.9-S1 -> 9.9.9-S6, 9.11.0-9.11.0-P12019-01-16
CVE-2016-9778 [MEDIUM] CWE-388 CVE-2016-9778: An error in handling certain queries can cause an assertion failure when a server is using the nxdom An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the vulnerability and if the attacker
nvd
CVE-2017-3140P3MEDIUMCVSS 5.9v9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S12019-01-16
CVE-2017-3140 [MEDIUM] CWE-400 CVE-2017-3140: If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can le If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.
nvd
CVE-2017-3138P3MEDIUMCVSS 5.3v9.9.9->9.9.9-P7, 9.9.10b1->9.9.10rc2, 9.10.4->9.10.4-P7, 9.10.5b1->9.10.5rc2, 9.11.0->9.11.0-P4, 9.11.1b1->9.11.1rc2, 9.9.9-S1->9.9.9-S92019-01-16
CVE-2017-3138 [MEDIUM] CWE-617 CVE-2017-3138: named contains a feature which allows operators to issue commands to a running server by communicati named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to exit with a REQUIRE assertion failure
nvd
CVE-2026-10822P3MEDIUMCVSS 6.5≥ 9.18.0, ≤ 9.18.50≥ 9.20.0, ≤ 9.20.24+3 more2026-07-22
CVE-2026-10822 [MEDIUM] CWE-617 CVE-2026-10822: If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid d If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual i
nvd
CVE-2026-5947P3MEDIUMCVSS 5.9≥ 9.20.0, ≤ 9.20.22≥ 9.21.0, ≤ 9.21.21+1 more2026-05-20
CVE-2026-5947 [MEDIUM] CWE-362 CVE-2026-5947: Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIN Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients" limit is reached (as would occur during a query flood), and that same DNS message is discarded per the li
nvd
Isc Bind 9 vulnerabilities | cvebase