CVE-2021-25215
An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
Vexday Risk Score
26Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 11.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
29 Apr 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In short
A bug in BIND DNS software causes the server to crash when processing certain DNS queries for DNAME records. An attacker can send a specially crafted query to make the DNS service stop working.
Technical detail
The vulnerability exists in BIND's DNAME record processing logic where a failed assertion check causes the named process to terminate. An unauthenticated attacker can trigger a denial of service by sending a query for a DNAME record that requires recursive processing, affecting BIND versions 9.0.0 through 9.17.11 across multiple branches.
Summary generated and translated by AI from the official description.
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
ISC · BIND9Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://kb.isc.org/v1/docs/cve-2021-25215https://lists.debian.org/debian-lts-announce/2021/05/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VEC2XG4Q2ODTN2C4CGXEIXU3EUTBMK7L/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZDSRPCJQ7MZC6CENH5PO3VQOFI7VSWBE/https://security.netapp.com/advisory/ntap-20210521-0006/https://www.debian.org/security/2021/dsa-4909https://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://www.openwall.com/lists/oss-security/2021/04/29/1http://www.openwall.com/lists/oss-security/2021/04/29/2http://www.openwall.com/lists/oss-security/2021/04/29/3http://www.openwall.com/lists/oss-security/2021/04/29/4