A truncated TSIG response can lead to an assertion failure
Published Aug 21, 2020
6.5
MEDIUMCVSS 3.1
EPSS 5.59%
Description
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.
Affected products
-
- Version 9.0.0StatusaffectedConstraints<unspecified
- Version 9.12.0StatusaffectedConstraints<unspecified
- Version 9.17.0StatusaffectedConstraints<unspecified
- Version 9.9.3-S1StatusaffectedConstraints<Supported Preview*
- Version unspecifiedStatusaffectedConstraints<9.11.22
- Version unspecifiedStatusaffectedConstraints<9.16.6
- Version unspecifiedStatusaffectedConstraints<9.17.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
Configuration 3
- 31
- 32
Configuration 4
- 9.0
- 10.0
Configuration 5
- 12.04
- 14.04
- 16.04
- 18.04
- 20.04
Configuration 6
- n/a
Configuration 8
- < 2.2.2-5028
Configuration 9
- ≥ 8.0.0 · ≤ 8.5.0
No data.
Red Hat Enterprise Linux 6
bind-32:9.8.2-0.68.rc1.el6_10.8
Fixed · RHSA-2020:4183
Red Hat Enterprise Linux 7
bind-32:9.11.4-26.P2.el7_9.2
Fixed · RHSA-2020:5011
Red Hat Enterprise Linux 7.6 Extended Update Support
bind-32:9.9.4-74.el7_6.5
Fixed · RHSA-2020:4992
Red Hat Enterprise Linux 7.7 Extended Update Support
bind-32:9.11.4-9.P2.el7_7.3
Fixed · RHSA-2020:5203
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8
Fixed · RHSA-2020:4500
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8
Fixed · RHSA-2020:4500
Red Hat Enterprise Linux 5
bind
Out of support scope
Red Hat Enterprise Linux 5
bind97
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | bind-32:9.8.2-0.68.rc1.el6_10.8 | Fixed | RHSA-2020:4183 |
| Red Hat Enterprise Linux 7 | bind-32:9.11.4-26.P2.el7_9.2 | Fixed | RHSA-2020:5011 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | bind-32:9.9.4-74.el7_6.5 | Fixed | RHSA-2020:4992 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | bind-32:9.11.4-9.P2.el7_7.3 | Fixed | RHSA-2020:5203 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8 | Fixed | RHSA-2020:4500 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8 | Fixed | RHSA-2020:4500 |
| Red Hat Enterprise Linux 5 | bind | Out of support scope | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND:
BIND 9.11.22 BIND 9.16.6 BIND 9.17.4
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
BIND 9.11.22-S1
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 5.59% (0.05591) | 92.66th | v5 (v2026.06.15) |
| Jun 15, 2026 | 5.54% (0.05545) | 91.80th | v5 (v2026.06.15) |
| Jan 31, 2026 | 2.40% (0.02402) | 84.70th | v4 (v2025.03.14) |
| Nov 21, 2025 | 0.67% (0.00673) | 70.62th | v4 (v2025.03.14) |
| Nov 18, 2025 | 10.86% (0.10859) | 92.65th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.45% (0.00451) | 60.79th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.86% (0.01862) | 72.02th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.45% (0.00451) | 61.59th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.41% (0.00408) | 74.66th | v3 (v2023.03.01) |
| Jul 11, 2024 | 0.41% (0.00408) | 74.01th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.43% (0.00425) | 73.64th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.43% (0.00425) | 70.33th | v3 (v2023.03.01) |
| Mar 6, 2023 | 11.00% (0.10998) | 94.86th | v2 (v2022.01.01) |
| Apr 1, 2022 | 11.00% (0.10998) | 94.44th | v2 (v2022.01.01) |
| Feb 4, 2022 | 55.90% (0.55898) | 98.48th | v2 (v2022.01.01) |
| Feb 3, 2022 | 11.74% (0.11741) | 88.45th | v1 |
| Jan 6, 2022 | 11.74% (0.11741) | 88.31th | v1 |
| Oct 21, 2021 | 2.88% (0.02880) | 80.93th | v1 |
| Sep 1, 2021 | 2.68% (0.02678) | 79.35th | v1 |
| Apr 14, 2021 | 2.68% (0.02678) | 0.00th | v1 |
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8622 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1869473 Issue Tracking
- https://kb.isc.org/docs/cve-2020-8622 x_refsource_CONFIRMVendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/08/msg00053.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQN62GBMCIC5AY4KYADGXNKVY6AJKSJE/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKAMJZXR66P6S5LEU4SN7USSNCWTXEXP/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-8622
- https://security.gentoo.org/glsa/202008-19 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200827-0003/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4468-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/4468-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8622
- https://www.debian.org/security/2020/dsa-4752 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.synology.com/security/advisory/Synology_SA_20_19 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.