Back

MEDIUM

A broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly

Published Apr 29, 2021

Description

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND:

BIND 9.11.31 BIND 9.16.15 BIND 9.17.12

BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.

BIND 9.11.31-S1 BIND 9.16.15-S1

Red Hat mitigation

Disabling incremental zone transfers (IXFR) by setting "request-ixfr no;" in the desired configuration block (options, zone, or server) prevents the failing assertion from being evaluated.

Metrics

Weaknesses (1)

References (16)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Apr 29, 2021
Updated Sep 17, 2024
Reserved Jan 15, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Apr 28, 2021