A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Published Apr 29, 2021
9.8
CRITICALCVSS 3.1
EPSS 82.37%
Description
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.
Affected products
-
- Version Development Branch 9.17 9.17.0 through versions before 9.17.2StatusaffectedConstraints-
- Version Open Source Branches 9.12 though 9.16 9.12.0 through versions before 9.16.14StatusaffectedConstraints-
- Version Open Source Branches 9.5 though 9.11 9.5.0 through versions before 9.11.31StatusaffectedConstraints-
- Version Supported Preview Branch 9.11-S 9.11.3-S1 through versions before 9.11.31-S1StatusaffectedConstraints-
- Version Supported Preview Branch 9.16-S 9.16.8-S1 through versions before 9.16.14-S1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ISC | BIND9 | n/a |
|
Configuration 1
- 9.0
- 10.0
Configuration 2
- ≥ 9.0.0 · < 9.11.31
- ≥ 9.12.0 · < 9.16.15
- ≥ 9.17.0 · < 9.17.12
- 9.9.3
- 9.9.12
- 9.9.13
- 9.10.5
- 9.10.7
- 9.11.3
- 9.11.5
- 9.11.5
- 9.11.5
- 9.11.6
- 9.11.7
- 9.11.8
- 9.11.12
- 9.11.21
- 9.11.27
- 9.11.29
- 9.16.8
- 9.16.11
- 9.16.13
Configuration 3
- < 1.0.1.1
Configuration 4
- n/a
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
No data.
Red Hat Enterprise Linux 5
bind
Not affected
Red Hat Enterprise Linux 5
bind97
Not affected
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 9
bind
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 5 | bind97 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | bind | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND:
BIND 9.11.31 BIND 9.16.15 BIND 9.17.12
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
BIND 9.11.31-S1 BIND 9.16.15-S1
Red Hat statement
Versions of bind package shipped with Red Hat Enterprise Linux do not enable ISC SPNEGO and therefore are not affected by this flaw.
Red Hat mitigation
This vulnerability only affects servers configured to use GSS-TSIG, most often to sign dynamic updates. If another mechanism can be used to authenticate updates, the vulnerability can be avoided by choosing not to enable the use of GSS-TSIG features.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1 other source (CVE.org) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (75 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 82.37% (0.82367) | 99.65th | v5 (v2026.06.15) |
| Jul 10, 2026 | 82.37% (0.82367) | 99.62th | v5 (v2026.06.15) |
| Jun 15, 2026 | 83.41% (0.83406) | 99.64th | v5 (v2026.06.15) |
| Mar 4, 2026 | 27.74% (0.27744) | 96.35th | v4 (v2025.03.14) |
| Mar 1, 2026 | 61.24% (0.61237) | 98.29th | v4 (v2025.03.14) |
| Feb 18, 2026 | 27.74% (0.27744) | 96.33th | v4 (v2025.03.14) |
| Feb 4, 2026 | 31.41% (0.31412) | 96.65th | v4 (v2025.03.14) |
| Feb 1, 2026 | 71.37% (0.71367) | 98.69th | v4 (v2025.03.14) |
| Jan 17, 2026 | 31.41% (0.31412) | 96.63th | v4 (v2025.03.14) |
| Jan 4, 2026 | 16.00% (0.16004) | 94.55th | v4 (v2025.03.14) |
| Jan 1, 2026 | 60.65% (0.60654) | 98.22th | v4 (v2025.03.14) |
| Dec 6, 2025 | 16.00% (0.16004) | 94.51th | v4 (v2025.03.14) |
| Dec 4, 2025 | 17.91% (0.17909) | 94.88th | v4 (v2025.03.14) |
| Dec 1, 2025 | 63.30% (0.63300) | 98.32th | v4 (v2025.03.14) |
| Nov 21, 2025 | 17.91% (0.17909) | 94.87th | v4 (v2025.03.14) |
| Nov 18, 2025 | 88.70% (0.88704) | 99.60th | v4 (v2025.03.14) |
| Nov 16, 2025 | 17.91% (0.17909) | 94.86th | v4 (v2025.03.14) |
| Nov 5, 2025 | 16.26% (0.16262) | 94.54th | v4 (v2025.03.14) |
| Nov 4, 2025 | 14.57% (0.14570) | 94.17th | v4 (v2025.03.14) |
| Nov 1, 2025 | 54.50% (0.54499) | 97.91th | v4 (v2025.03.14) |
| Oct 17, 2025 | 12.58% (0.12581) | 93.62th | v4 (v2025.03.14) |
| Oct 4, 2025 | 20.50% (0.20503) | 95.35th | v4 (v2025.03.14) |
| Oct 1, 2025 | 53.54% (0.53544) | 97.92th | v4 (v2025.03.14) |
| Sep 14, 2025 | 24.73% (0.24725) | 95.94th | v4 (v2025.03.14) |
| Sep 11, 2025 | 22.16% (0.22162) | 95.59th | v4 (v2025.03.14) |
| Sep 4, 2025 | 24.73% (0.24725) | 95.95th | v4 (v2025.03.14) |
| Sep 1, 2025 | 45.25% (0.45246) | 97.54th | v4 (v2025.03.14) |
| Aug 5, 2025 | 24.73% (0.24725) | 95.91th | v4 (v2025.03.14) |
| Aug 1, 2025 | 45.25% (0.45246) | 97.51th | v4 (v2025.03.14) |
| Jul 4, 2025 | 24.73% (0.24725) | 95.87th | v4 (v2025.03.14) |
| Jul 1, 2025 | 45.25% (0.45246) | 97.46th | v4 (v2025.03.14) |
| Jun 4, 2025 | 24.73% (0.24725) | 95.84th | v4 (v2025.03.14) |
| Jun 1, 2025 | 45.25% (0.45246) | 97.45th | v4 (v2025.03.14) |
| May 4, 2025 | 24.73% (0.24725) | 95.80th | v4 (v2025.03.14) |
| May 1, 2025 | 45.25% (0.45246) | 97.43th | v4 (v2025.03.14) |
| Apr 29, 2025 | 24.73% (0.24725) | 95.78th | v4 (v2025.03.14) |
| Apr 24, 2025 | 13.01% (0.13006) | 93.65th | v4 (v2025.03.14) |
| Apr 17, 2025 | 5.69% (0.05687) | 89.86th | v4 (v2025.03.14) |
| Apr 16, 2025 | 12.54% (0.12537) | 93.52th | v4 (v2025.03.14) |
| Apr 13, 2025 | 5.69% (0.05687) | 89.52th | v4 (v2025.03.14) |
| Apr 12, 2025 | 12.54% (0.12537) | 93.35th | v4 (v2025.03.14) |
| Mar 30, 2025 | 5.69% (0.05687) | 89.46th | v4 (v2025.03.14) |
| Mar 29, 2025 | 25.86% (0.25862) | 93.97th | v4 (v2025.03.14) |
| Mar 22, 2025 | 5.69% (0.05687) | 89.58th | v4 (v2025.03.14) |
| Mar 21, 2025 | 12.54% (0.12537) | 93.39th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.69% (0.05687) | 89.71th | v4 (v2025.03.14) |
| Mar 3, 2025 | 31.50% (0.31495) | 97.09th | v3 (v2023.03.01) |
| Dec 17, 2024 | 24.89% (0.24893) | 96.66th | v3 (v2023.03.01) |
| May 15, 2024 | 44.74% (0.44738) | 97.38th | v3 (v2023.03.01) |
| May 1, 2024 | 38.78% (0.38781) | 97.20th | v3 (v2023.03.01) |
| Apr 16, 2024 | 33.62% (0.33623) | 97.00th | v3 (v2023.03.01) |
| Jan 12, 2024 | 26.78% (0.26778) | 96.32th | v3 (v2023.03.01) |
| Dec 30, 2023 | 28.67% (0.28670) | 96.42th | v3 (v2023.03.01) |
| Dec 3, 2023 | 27.52% (0.27525) | 96.32th | v3 (v2023.03.01) |
| Oct 25, 2023 | 23.92% (0.23919) | 96.04th | v3 (v2023.03.01) |
| Sep 14, 2023 | 25.83% (0.25833) | 96.12th | v3 (v2023.03.01) |
| Aug 18, 2023 | 27.07% (0.27067) | 96.18th | v3 (v2023.03.01) |
| Aug 2, 2023 | 23.97% (0.23975) | 95.97th | v3 (v2023.03.01) |
| Jul 21, 2023 | 23.91% (0.23913) | 95.96th | v3 (v2023.03.01) |
| Jun 8, 2023 | 25.19% (0.25188) | 95.98th | v3 (v2023.03.01) |
| May 12, 2023 | 33.31% (0.33312) | 96.42th | v3 (v2023.03.01) |
| Apr 13, 2023 | 28.24% (0.28245) | 96.15th | v3 (v2023.03.01) |
| Mar 7, 2023 | 23.90% (0.23901) | 95.80th | v3 (v2023.03.01) |
| Mar 6, 2023 | 13.09% (0.13088) | 95.65th | v2 (v2022.01.01) |
| Apr 1, 2022 | 13.09% (0.13088) | 95.27th | v2 (v2022.01.01) |
| Feb 4, 2022 | 67.99% (0.67992) | 98.93th | v2 (v2022.01.01) |
| Feb 3, 2022 | 17.37% (0.17372) | 90.59th | v1 |
| Jan 6, 2022 | 17.37% (0.17372) | 90.48th | v1 |
| Sep 1, 2021 | 4.48% (0.04476) | 83.87th | v1 |
| Jun 8, 2021 | 4.48% (0.04476) | 0.00th | v1 |
| May 21, 2021 | 4.04% (0.04044) | 0.00th | v1 |
| May 5, 2021 | 3.61% (0.03608) | 0.00th | v1 |
| May 2, 2021 | 3.17% (0.03168) | 0.00th | v1 |
| Apr 30, 2021 | 2.73% (0.02725) | 0.00th | v1 |
| Apr 29, 2021 | 1.37% (0.01374) | 0.00th | v1 |
References (15)
- http://www.openwall.com/lists/oss-security/2021/04/29/1 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/04/29/2 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/04/29/3 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/04/29/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-25216 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1953872 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf x_refsource_CONFIRMPatchThird Party Advisory
- https://kb.isc.org/docs/cve-2021-25216
- https://kb.isc.org/v1/docs/cve-2021-25215 x_refsource_CONFIRMNot Applicable
- https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-25216
- https://security.netapp.com/advisory/ntap-20210521-0006/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-25216
- https://www.debian.org/security/2021/dsa-4909 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-657/ x_refsource_MISCThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.