Back

HIGH

An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself

Published Apr 29, 2021

Description

In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND:

BIND 9.11.31 BIND 9.16.15 BIND 9.17.12

BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.

BIND 9.11.31-S1 BIND 9.16.15-S1

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Metrics

Weaknesses (1)

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Apr 29, 2021
Updated Sep 16, 2024
Reserved Jan 15, 2021
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Apr 28, 2021