A flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
Published Jan 16, 2019
7.5
HIGHCVSS 3.1
EPSS 59.62%
Description
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.
Affected products
-
- Version BIND 9 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 2
- 6.0
- 7.0
- 6.0
- 7.0
- 7.6
- 7.5
- 7.6
- 6.0
- 7.0
Configuration 3
- 8.0
- 9.0
Configuration 4
- n/a
Configuration 5
- 12.04
- 14.04
- 16.04
- 18.04
No data.
Red Hat Enterprise Linux 6
bind-32:9.8.2-0.68.rc1.el6_10.1
Fixed · RHSA-2018:2571
Red Hat Enterprise Linux 7
bind-32:9.9.4-61.el7_5.1
Fixed · RHSA-2018:2570
Red Hat Enterprise Linux 5
bind
Not affected
Red Hat Enterprise Linux 5
bind97
Will not fix
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Virtualization 4
bind
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | bind-32:9.8.2-0.68.rc1.el6_10.1 | Fixed | RHSA-2018:2571 |
| Red Hat Enterprise Linux 7 | bind-32:9.9.4-61.el7_5.1 | Fixed | RHSA-2018:2570 |
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Virtualization 4 | bind | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Most operators will not need to make any changes unless they are using the "deny-answer-aliases" feature (which is described in the BIND 9 Adminstrator Reference Manual section 6.2.) "deny-answer-aliases" is off by default; only configurations which explicitly enable it can be affected by this defect.
If you are using "deny-answer-aliases", upgrade to the patched release most closely related to your current version of BIND.
9.9.13-P1 9.10.8-P1 9.11.4-P1 9.12.2-P1
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
9.11.3-S3
Red Hat statement
The "deny-answer-aliases" configuration option is not enabled in default configurations of bind. Upstream states that this option is very rarely used. As such, if customers have not specifically enabled this option in configurations, the risk should be mitigated.
Red Hat mitigation
Disabling the "deny-answer-aliases" configuration option should prevent exploitation.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (38 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 59.62% (0.59620) | 99.10th | v5 (v2026.06.15) |
| Jun 23, 2026 | 59.35% (0.59353) | 99.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 73.18% (0.73184) | 99.38th | v5 (v2026.06.15) |
| Apr 13, 2026 | 64.53% (0.64530) | 98.45th | v4 (v2025.03.14) |
| Mar 3, 2026 | 75.02% (0.75021) | 98.86th | v4 (v2025.03.14) |
| Nov 30, 2025 | 69.02% (0.69020) | 98.56th | v4 (v2025.03.14) |
| Nov 21, 2025 | 57.94% (0.57937) | 98.06th | v4 (v2025.03.14) |
| Nov 18, 2025 | 86.46% (0.86463) | 99.50th | v4 (v2025.03.14) |
| Aug 1, 2025 | 58.05% (0.58047) | 98.10th | v4 (v2025.03.14) |
| Jun 19, 2025 | 69.52% (0.69522) | 98.54th | v4 (v2025.03.14) |
| May 17, 2025 | 66.03% (0.66033) | 98.39th | v4 (v2025.03.14) |
| Apr 29, 2025 | 58.29% (0.58293) | 98.03th | v4 (v2025.03.14) |
| Apr 20, 2025 | 52.44% (0.52437) | 97.74th | v4 (v2025.03.14) |
| Mar 30, 2025 | 39.25% (0.39246) | 96.99th | v4 (v2025.03.14) |
| Mar 29, 2025 | 60.24% (0.60237) | 97.53th | v4 (v2025.03.14) |
| Mar 28, 2025 | 39.25% (0.39246) | 96.99th | v4 (v2025.03.14) |
| Mar 27, 2025 | 60.24% (0.60237) | 98.01th | v4 (v2025.03.14) |
| Mar 22, 2025 | 52.15% (0.52147) | 97.72th | v4 (v2025.03.14) |
| Mar 20, 2025 | 51.00% (0.51003) | 97.66th | v4 (v2025.03.14) |
| Mar 19, 2025 | 62.50% (0.62499) | 98.17th | v4 (v2025.03.14) |
| Mar 17, 2025 | 51.00% (0.51003) | 97.60th | v4 (v2025.03.14) |
| Mar 13, 2025 | 81.46% (0.81460) | 98.66th | v3 (v2023.03.01) |
| Dec 26, 2024 | 83.74% (0.83738) | 98.69th | v3 (v2023.03.01) |
| Dec 17, 2024 | 81.82% (0.81824) | 98.61th | v3 (v2023.03.01) |
| Dec 12, 2024 | 94.39% (0.94391) | 99.31th | v3 (v2023.03.01) |
| Jul 18, 2024 | 94.77% (0.94766) | 99.29th | v3 (v2023.03.01) |
| May 23, 2024 | 94.39% (0.94391) | 99.20th | v3 (v2023.03.01) |
| Mar 3, 2024 | 95.32% (0.95322) | 99.29th | v3 (v2023.03.01) |
| Feb 8, 2024 | 95.65% (0.95649) | 99.34th | v3 (v2023.03.01) |
| Jan 10, 2024 | 96.35% (0.96352) | 99.45th | v3 (v2023.03.01) |
| Mar 7, 2023 | 96.28% (0.96284) | 99.18th | v3 (v2023.03.01) |
| Mar 6, 2023 | 68.06% (0.68064) | 99.11th | v2 (v2022.01.01) |
| Feb 4, 2022 | 68.06% (0.68064) | 98.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 13.16% (0.13161) | 89.02th | v1 |
| Jan 6, 2022 | 13.16% (0.13161) | 88.89th | v1 |
| Nov 2, 2021 | 13.16% (0.13161) | 96.08th | v1 |
| Sep 1, 2021 | 12.39% (0.12387) | 95.89th | v1 |
| Apr 14, 2021 | 12.39% (0.12387) | 0.00th | v1 |
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00027.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/105055 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041436 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2570 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:2571 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-5740 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1613595 Issue Tracking
- https://kb.isc.org/article/AA-01639/74/CVE-2018-5740
- https://kb.isc.org/docs/aa-01639 x_refsource_CONFIRMVendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00033.html mailing-listx_refsource_MLISTThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-5740
- https://security.gentoo.org/glsa/201903-13 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20180926-0003/ x_refsource_CONFIRMThird Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03927en_us x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/3769-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3769-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-5740
Change history (0)
No recorded changes yet.