A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use
Published Aug 18, 2021
7.5
HIGHCVSS 3.1
EPSS 3.59%
Description
In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion check. The vulnerability affects only BIND 9 releases 9.16.19, 9.17.16, and release 9.16.19-S1 of the BIND Supported Preview Edition.
Affected products
-
- Version Development Branch 9.17.16StatusaffectedConstraints-
- Version Stable Branch 9.16.19StatusaffectedConstraints-
- Version Supported Preview Edition 9.16.19-S1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
Red Hat Enterprise Linux 6
bind
Not affected
Red Hat Enterprise Linux 7
bind
Not affected
Red Hat Enterprise Linux 8
bind
Not affected
Red Hat Enterprise Linux 9
bind
Not affected
Red Hat Virtualization 4
redhat-virtualization-host
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 7 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 8 | bind | Not affected | n/a |
| Red Hat Enterprise Linux 9 | bind | Not affected | n/a |
| Red Hat Virtualization 4 | redhat-virtualization-host | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND:
BIND 9.16.20 BIND 9.17.17
BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers.
BIND 9.16.20-S1
Red Hat statement
An attacker may abuse the Path MTU discovery (PMTUD) protocol to trick bind into exceeding the interface MTU. Response Rate Limiting (RRL) is not enabled by default for user defined views nor the builtin one, but it is enabled by default for the default builtin CHAOS class view, which bind uses to provide various information. This issue did not affect the versions of bind as shipped with Red Hat Enterprise Linux 6, 7, and 8 as they provide an older version of the code which does not allow to trigger the assertion.
Red Hat mitigation
Disabling RRL in all views, including the builtin CHAOS class view, prevents the faulty assertion from being reached in the vulnerable versions of bind. To do that you can remove `rate-limit` from your named.conf files and provide a replacement for the builtin CHAOS view, like the one below: ``` view override_bind chaos { recursion no; notify no; allow-new-zones no; max-cache-size 2M; zone "version.bind" chaos { type primary; database "_builtin version"; }; zone "hostname.bind" chaos { type primary; database "_builtin hostname"; }; zone "authors.bind" chaos { type primary; database "_builtin authors"; }; zone "id.server" chaos { type primary; database "_builtin id"; }; }; ```
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.59% (0.03589) | 89.05th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.56% (0.03559) | 87.79th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.40% (0.00396) | 58.30th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.21% (0.00206) | 59.49th | v3 (v2023.03.01) |
| May 3, 2024 | 0.21% (0.00206) | 58.35th | v3 (v2023.03.01) |
| Mar 24, 2024 | 0.18% (0.00181) | 54.38th | v3 (v2023.03.01) |
| Apr 9, 2023 | 0.15% (0.00149) | 49.50th | v3 (v2023.03.01) |
| Mar 11, 2023 | 0.13% (0.00126) | 45.52th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.11% (0.00109) | 42.18th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.63% (0.01626) | 75.89th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.63% (0.01626) | 75.84th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.63% (0.01626) | 73.79th | v2 (v2022.01.01) |
| Feb 4, 2022 | 11.05% (0.11049) | 88.53th | v2 (v2022.01.01) |
| Feb 3, 2022 | 5.36% (0.05363) | 79.74th | v1 |
| Jan 6, 2022 | 5.36% (0.05363) | 79.54th | v1 |
| Sep 9, 2021 | 1.25% (0.01247) | 68.56th | v1 |
| Sep 1, 2021 | 1.04% (0.01040) | 64.49th | v1 |
| Aug 21, 2021 | 1.04% (0.01040) | 0.00th | v1 |
| Aug 19, 2021 | 0.62% (0.00624) | 0.00th | v1 |
References (10)
- http://www.openwall.com/lists/oss-security/2021/08/18/3 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/08/20/2 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-25218 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1995312 Issue Tracking
- https://kb.isc.org/docs/cve-2021-25218
- https://kb.isc.org/v1/docs/cve-2021-25218 x_refsource_CONFIRMExploitVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPJCLGSR4BTGFLBLGIE5TEQP2SNJKGVL/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2021-25218
- https://security.netapp.com/advisory/ntap-20210909-0002/ x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2021-25218
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2021/08/18/3 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2021/08/20/2 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2021-25218 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1995312 | Issue Tracking | |
| https://kb.isc.org/docs/cve-2021-25218 | ||
| https://kb.isc.org/v1/docs/cve-2021-25218 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZPJCLGSR4BTGFLBLGIE5TEQP2SNJKGVL/ | vendor-advisoryx_refsource_FEDORA | |
| https://nvd.nist.gov/vuln/detail/CVE-2021-25218 | ||
| https://security.netapp.com/advisory/ntap-20210909-0002/ | x_refsource_CONFIRMThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2021-25218 |
Change history (0)
No recorded changes yet.