BIND 9.12's serve-stale implementation can cause an assertion failure in rbtdb.c or other undesirable behavior, even if serve-stale is not enabled.
Published Jan 16, 2019
7.5
HIGHCVSS 3.0
EPSS 10.44%
Description
A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-stale feature and NSEC aggressive negative caching can in some cases cause undesirable behavior from named, such as a recursion loop or excessive logging. Deliberate exploitation of this condition could cause operational problems depending on the particular manifestation -- either degradation or denial of service. Affects BIND 9.12.0 and 9.12.1.
Affected products
-
- Version 9.12.0 and 9.12.1StatusaffectedConstraints-
- Version
Configuration 2
- n/a
- n/a
No data.
Red Hat Enterprise Linux 5
bind
Not affected
Red Hat Enterprise Linux 5
bind97
Not affected
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
The error which can be exploited in this vulnerability is present in only two public release versions of BIND, 9.12.0 and 9.12.1. If you are running an affected version then upgrade to BIND 9.12.1-P2
Red Hat statement
This security flaw only affects bind versions 9.12.0 and 9.12.1. Since Red Hat Enterprise Linux does not ship any of these bind versions, it is not affected.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (CVE.org) ▾
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (23 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 10.44% (0.10438) | 95.61th | v5 (v2026.06.15) |
| Jun 23, 2026 | 10.36% (0.10355) | 95.12th | v5 (v2026.06.15) |
| Jun 15, 2026 | 12.32% (0.12318) | 95.66th | v5 (v2026.06.15) |
| Nov 21, 2025 | 1.23% (0.01232) | 78.58th | v4 (v2025.03.14) |
| Nov 18, 2025 | 5.32% (0.05320) | 89.04th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.91% (0.00912) | 73.74th | v4 (v2025.03.14) |
| Mar 29, 2025 | 3.85% (0.03849) | 80.04th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.95% (0.00951) | 83.35th | v3 (v2023.03.01) |
| Mar 2, 2024 | 0.95% (0.00951) | 82.74th | v3 (v2023.03.01) |
| Feb 8, 2024 | 1.88% (0.01884) | 88.03th | v3 (v2023.03.01) |
| Jan 10, 2024 | 3.15% (0.03153) | 90.13th | v3 (v2023.03.01) |
| Jul 8, 2023 | 3.73% (0.03730) | 90.50th | v3 (v2023.03.01) |
| Jun 14, 2023 | 2.65% (0.02654) | 88.88th | v3 (v2023.03.01) |
| May 8, 2023 | 2.79% (0.02785) | 89.06th | v3 (v2023.03.01) |
| Mar 7, 2023 | 3.91% (0.03911) | 90.59th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.63% (0.01626) | 75.89th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.63% (0.01626) | 75.84th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.63% (0.01626) | 73.79th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.63% (0.01626) | 52.68th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.29% (0.01294) | 30.79th | v1 |
| Jan 6, 2022 | 1.29% (0.01294) | 30.15th | v1 |
| Sep 1, 2021 | 1.29% (0.01294) | 69.02th | v1 |
| Apr 14, 2021 | 1.29% (0.01294) | 0.00th | v1 |
References (9)
- http://www.securityfocus.com/bid/104236 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1040942 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-5737 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1578593 Issue Tracking
- https://kb.isc.org/article/AA-01606/74/CVE-2018-5737
- https://kb.isc.org/docs/aa-01606 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-5737
- https://security.netapp.com/advisory/ntap-20180926-0004/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-5737
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/104236 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securitytracker.com/id/1040942 | vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-5737 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1578593 | Issue Tracking | |
| https://kb.isc.org/article/AA-01606/74/CVE-2018-5737 | ||
| https://kb.isc.org/docs/aa-01606 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-5737 | ||
| https://security.netapp.com/advisory/ntap-20180926-0004/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2018-5737 |
Change history (0)
No recorded changes yet.