A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Published Feb 17, 2021
8.1
HIGHCVSS 3.1
EPSS 64.16%
Description
BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. The most likely outcome of a successful exploitation of the vulnerability is a crash of the named process. However, remote code execution, while unproven, is theoretically possible. Affects: BIND 9.5.0 -> 9.11.27, 9.12.0 -> 9.16.11, and versions BIND 9.11.3-S1 -> 9.11.27-S1 and 9.16.8-S1 -> 9.16.11-S1 of BIND Supported Preview Edition. Also release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch
Affected products
-
- Version Development Branch 9.17 9.17.0 through versions before 9.17.2StatusaffectedConstraints-
- Version Open Source Branches 9.12 though 9.16 9.12.0 through versions before 9.16.12StatusaffectedConstraints-
- Version Open Source Branches 9.5 though 9.11 9.5.0 through versions before 9.11.28StatusaffectedConstraints-
- Version Supported Preview Branch 9.11-S 9.11.3-S1 through versions before 9.11.28-S1StatusaffectedConstraints-
- Version Supported Preview Branch 9.16-S 9.16.8-S1 through versions before 9.16.12-S1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ISC | BIND9 | n/a |
|
Configuration 1
- ≥ 9.5.0 · ≤ 9.11.27
- ≥ 9.12.0 · ≤ 9.16.11
- 9.11.3
- 9.11.5
- 9.11.5
- 9.11.6
- 9.11.7
- 9.11.8
- 9.11.21
- 9.11.27
- 9.16.8
- 9.16.11
- 9.17.0
- 9.17.1
Configuration 2
- 9.0
- 10.0
Configuration 3
- 32
- 33
- 34
Configuration 4
- < 1.0.1.1
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support
bind-32:9.8.2-0.68.rc1.el6_10.10
Fixed · RHSA-2021:0672
Red Hat Enterprise Linux 7
bind-32:9.11.4-26.P2.el7_9.4
Fixed · RHSA-2021:0671
Red Hat Enterprise Linux 7.2 Advanced Update Support
bind-32:9.9.4-29.el7_2.10
Fixed · RHSA-2021:0694
Red Hat Enterprise Linux 7.3 Advanced Update Support
bind-32:9.9.4-50.el7_3.5
Fixed · RHSA-2021:0693
Red Hat Enterprise Linux 7.4 Advanced Update Support
bind-32:9.9.4-51.el7_4.5
Fixed · RHSA-2021:0692
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
bind-32:9.9.4-51.el7_4.5
Fixed · RHSA-2021:0692
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
bind-32:9.9.4-51.el7_4.5
Fixed · RHSA-2021:0692
Red Hat Enterprise Linux 7.6 Extended Update Support
bind-32:9.9.4-74.el7_6.6
Fixed · RHSA-2021:0691
Red Hat Enterprise Linux 7.7 Extended Update Support
bind-32:9.11.4-9.P2.el7_7.4
Fixed · RHSA-2021:0727
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8_3.1
Fixed · RHSA-2021:0670
Red Hat Enterprise Linux 8
bind-32:9.11.20-5.el8_3.1
Fixed · RHSA-2021:0670
Red Hat Enterprise Linux 8.1 Extended Update Support
bind-32:9.11.4-26.P2.el8_1.4
Fixed · RHSA-2021:0669
Red Hat Enterprise Linux 8.2 Extended Update Support
bind-32:9.11.13-6.el8_2.2
Fixed · RHSA-2021:0922
Red Hat Enterprise Linux 5
bind
Not affected
Red Hat Enterprise Linux 5
bind97
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support | bind-32:9.8.2-0.68.rc1.el6_10.10 | Fixed | RHSA-2021:0672 |
| Red Hat Enterprise Linux 7 | bind-32:9.11.4-26.P2.el7_9.4 | Fixed | RHSA-2021:0671 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | bind-32:9.9.4-29.el7_2.10 | Fixed | RHSA-2021:0694 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | bind-32:9.9.4-50.el7_3.5 | Fixed | RHSA-2021:0693 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | bind-32:9.9.4-51.el7_4.5 | Fixed | RHSA-2021:0692 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | bind-32:9.9.4-51.el7_4.5 | Fixed | RHSA-2021:0692 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | bind-32:9.9.4-51.el7_4.5 | Fixed | RHSA-2021:0692 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | bind-32:9.9.4-74.el7_6.6 | Fixed | RHSA-2021:0691 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | bind-32:9.11.4-9.P2.el7_7.4 | Fixed | RHSA-2021:0727 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8_3.1 | Fixed | RHSA-2021:0670 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.20-5.el8_3.1 | Fixed | RHSA-2021:0670 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | bind-32:9.11.4-26.P2.el8_1.4 | Fixed | RHSA-2021:0669 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | bind-32:9.11.13-6.el8_2.2 | Fixed | RHSA-2021:0922 |
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND:
BIND 9.11.28 BIND 9.16.12
BIND Supported Preview Edition is a special feature-preview branch of BIND provided to eligible ISC support customers.
BIND 9.11.28-S1 BIND 9.16.12-S1
Acknowledgments: ISC would like to thank an anonymous party, working in conjunction with Trend Micro Zero Day Initiative, for reporting this issue to us.
Red Hat statement
BIND servers shipped with Red Hat Enterprise Linux are compiled with GSS-TSIG and are therefore affected by this flaw. However, these BIND packages use the default settings and are not vulnerable by default.
Red Hat mitigation
As per upstream: BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings, the vulnerable code path is NOT exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. This vulnerability only affects servers configured to use GSS-TSIG, most often to sign dynamic updates. If another mechanism can be used to authenticate updates, the vulnerability can be avoided by choosing not to enable the use of GSS-TSIG features.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (43 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 64.16% (0.64161) | 99.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 64.16% (0.64161) | 99.12th | v5 (v2026.06.15) |
| May 1, 2026 | 25.15% (0.25150) | 96.20th | v4 (v2025.03.14) |
| Mar 4, 2026 | 26.30% (0.26304) | 96.20th | v4 (v2025.03.14) |
| Mar 3, 2026 | 40.16% (0.40159) | 97.28th | v4 (v2025.03.14) |
| Mar 1, 2026 | 19.50% (0.19495) | 95.30th | v4 (v2025.03.14) |
| Feb 4, 2026 | 11.06% (0.11064) | 93.26th | v4 (v2025.03.14) |
| Feb 1, 2026 | 19.50% (0.19495) | 95.26th | v4 (v2025.03.14) |
| Jan 31, 2026 | 11.06% (0.11064) | 93.25th | v4 (v2025.03.14) |
| Dec 4, 2025 | 2.12% (0.02118) | 83.58th | v4 (v2025.03.14) |
| Dec 1, 2025 | 3.43% (0.03426) | 87.10th | v4 (v2025.03.14) |
| Nov 21, 2025 | 2.12% (0.02118) | 83.58th | v4 (v2025.03.14) |
| Nov 18, 2025 | 81.54% (0.81542) | 99.26th | v4 (v2025.03.14) |
| May 1, 2025 | 2.68% (0.02683) | 85.07th | v4 (v2025.03.14) |
| Apr 6, 2025 | 3.70% (0.03699) | 86.89th | v4 (v2025.03.14) |
| Apr 5, 2025 | 2.68% (0.02683) | 84.60th | v4 (v2025.03.14) |
| Mar 30, 2025 | 3.71% (0.03709) | 86.86th | v4 (v2025.03.14) |
| Mar 29, 2025 | 6.58% (0.06576) | 84.84th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.71% (0.03709) | 87.17th | v4 (v2025.03.14) |
| Mar 13, 2025 | 61.01% (0.61008) | 98.02th | v3 (v2023.03.01) |
| Feb 24, 2025 | 63.61% (0.63608) | 98.06th | v3 (v2023.03.01) |
| Feb 10, 2025 | 67.54% (0.67538) | 98.17th | v3 (v2023.03.01) |
| Dec 22, 2024 | 60.84% (0.60843) | 97.94th | v3 (v2023.03.01) |
| Dec 17, 2024 | 47.90% (0.47903) | 97.55th | v3 (v2023.03.01) |
| Mar 6, 2024 | 18.73% (0.18732) | 96.08th | v3 (v2023.03.01) |
| Feb 21, 2024 | 19.91% (0.19905) | 96.18th | v3 (v2023.03.01) |
| Nov 8, 2023 | 21.57% (0.21565) | 95.93th | v3 (v2023.03.01) |
| Nov 3, 2023 | 26.90% (0.26898) | 96.24th | v3 (v2023.03.01) |
| Sep 24, 2023 | 28.79% (0.28794) | 96.29th | v3 (v2023.03.01) |
| Aug 29, 2023 | 27.46% (0.27456) | 96.19th | v3 (v2023.03.01) |
| Jul 8, 2023 | 23.62% (0.23619) | 95.92th | v3 (v2023.03.01) |
| Jun 21, 2023 | 25.41% (0.25414) | 96.02th | v3 (v2023.03.01) |
| May 24, 2023 | 21.45% (0.21450) | 95.71th | v3 (v2023.03.01) |
| May 12, 2023 | 22.29% (0.22291) | 95.78th | v3 (v2023.03.01) |
| May 8, 2023 | 23.51% (0.23512) | 95.83th | v3 (v2023.03.01) |
| Mar 7, 2023 | 25.81% (0.25810) | 95.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 13.09% (0.13088) | 95.65th | v2 (v2022.01.01) |
| Apr 1, 2022 | 13.09% (0.13088) | 95.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 67.99% (0.67992) | 98.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 18.79% (0.18794) | 93.67th | v1 |
| Jan 6, 2022 | 18.79% (0.18794) | 93.60th | v1 |
| Sep 1, 2021 | 4.91% (0.04905) | 87.49th | v1 |
| Apr 14, 2021 | 4.91% (0.04905) | 0.00th | v1 |
References (16)
- http://www.openwall.com/lists/oss-security/2021/02/19/1 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/02/20/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-8625 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1928486 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://kb.isc.org/docs/cve-2020-8625
- https://kb.isc.org/v1/docs/cve-2020-8625 x_refsource_CONFIRMMitigationVendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/02/msg00029.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EBTPWRQWRQEJNWY4NHO4WLS4KLJ3ERHZ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KYXAF7G45RXDVNUTWWCI2CVTHRZ67LST/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QWCMBOSZOJIIET7BWTRYS3HLX5TSDKHX/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-8625
- https://security.netapp.com/advisory/ntap-20210319-0001/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8625
- https://www.debian.org/security/2021/dsa-4857 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-195/ x_refsource_MISCThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.