DNS forwarders - cache poisoning vulnerability
Published Mar 23, 2022
6.8
MEDIUMCVSS 3.1
EPSS 3.36%
Description
BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.
Affected products
-
- Version Development Branch 9.17 BIND 9.17 all versionStatusaffectedConstraints-
- Version Open Source Branch 9.11 9.11.0 through versions before 9.11.37StatusaffectedConstraints-
- Version Open Source Branch 9.12-16 9.12.0 through versions before 9.16.27StatusaffectedConstraints-
- Version Open Source Branch 9.18 9.18.0StatusaffectedConstraints-
- Version Supported Preview Branch 9.11-S 9.11.0-S through versions before 9.11.37-SStatusaffectedConstraints-
- Version Supported Preview Branch 9.16-S 9.16.0-S through versions before 9.16.27-SStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| ISC | BIND | n/a |
|
Configuration 1
Configuration 2
- 34
- 35
- 36
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
Configuration 12
- < 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.3
- 21.3
- 21.3
- 21.3
- 21.3
- 21.3
- 21.3
- 21.3
- 21.4
- 21.4
- 21.4
- 21.4
- 21.4
- 22.1
- 22.1
- 22.2
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION
bind-32:9.8.2-0.68.rc1.el6_10.17
Fixed · RHSA-2025:23414
Red Hat Enterprise Linux 7
bind-32:9.11.4-26.P2.el7_9.13
Fixed · RHSA-2023:0402
Red Hat Enterprise Linux 8
bind-32:9.11.36-5.el8
Fixed · RHSA-2022:7790
Red Hat Enterprise Linux 8
bind-32:9.11.36-5.el8
Fixed · RHSA-2022:7790
Red Hat Enterprise Linux 8
bind9.16-32:9.16.23-0.9.el8.1
Fixed · RHSA-2022:7643
Red Hat Enterprise Linux 8.2 Advanced Update Support
bind-32:9.11.13-6.el8_2.11
Fixed · RHSA-2025:21741
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
bind-32:9.11.26-4.el8_4.8
Fixed · RHSA-2025:21740
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
bind-32:9.11.26-4.el8_4.8
Fixed · RHSA-2025:21740
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
bind9.16-32:9.16.23-0.7.el8_6.9
Fixed · RHSA-2025:22168
Red Hat Enterprise Linux 8.6 Extended Update Support
bind-32:9.11.36-3.el8_6.7
Fixed · RHSA-2024:2720
Red Hat Enterprise Linux 8.6 Extended Update Support
dhcp-12:4.3.6-47.el8_6.2
Fixed · RHSA-2024:2720
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
bind9.16-32:9.16.23-0.7.el8_6.9
Fixed · RHSA-2025:22168
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
bind9.16-32:9.16.23-0.7.el8_6.9
Fixed · RHSA-2025:22168
Red Hat Enterprise Linux 9
bind-32:9.16.23-5.el9_1
Fixed · RHSA-2022:8068
Red Hat Enterprise Linux 9
dhcp-12:4.4.2-17.b1.el9
Fixed · RHSA-2022:8385
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
bind-32:9.16.23-1.el9_0.11
Fixed · RHSA-2025:21889
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION | bind-32:9.8.2-0.68.rc1.el6_10.17 | Fixed | RHSA-2025:23414 |
| Red Hat Enterprise Linux 7 | bind-32:9.11.4-26.P2.el7_9.13 | Fixed | RHSA-2023:0402 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-5.el8 | Fixed | RHSA-2022:7790 |
| Red Hat Enterprise Linux 8 | bind-32:9.11.36-5.el8 | Fixed | RHSA-2022:7790 |
| Red Hat Enterprise Linux 8 | bind9.16-32:9.16.23-0.9.el8.1 | Fixed | RHSA-2022:7643 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | bind-32:9.11.13-6.el8_2.11 | Fixed | RHSA-2025:21741 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | bind-32:9.11.26-4.el8_4.8 | Fixed | RHSA-2025:21740 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | bind-32:9.11.26-4.el8_4.8 | Fixed | RHSA-2025:21740 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | bind9.16-32:9.16.23-0.7.el8_6.9 | Fixed | RHSA-2025:22168 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | bind-32:9.11.36-3.el8_6.7 | Fixed | RHSA-2024:2720 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | dhcp-12:4.3.6-47.el8_6.2 | Fixed | RHSA-2024:2720 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | bind9.16-32:9.16.23-0.7.el8_6.9 | Fixed | RHSA-2025:22168 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | bind9.16-32:9.16.23-0.7.el8_6.9 | Fixed | RHSA-2025:22168 |
| Red Hat Enterprise Linux 9 | bind-32:9.16.23-5.el9_1 | Fixed | RHSA-2022:8068 |
| Red Hat Enterprise Linux 9 | dhcp-12:4.4.2-17.b1.el9 | Fixed | RHSA-2022:8385 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | bind-32:9.16.23-1.el9_0.11 | Fixed | RHSA-2025:21889 |
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to the patched release most closely related to your current version of BIND: BIND 9.11.37 BIND 9.16.27 BIND 9.18.1 BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. BIND 9.11.37-S1 BIND 9.16.27-S1
Red Hat statement
Versions of BIND shipped with Red Hat Enterprise Linux 8, 9 are affected, because vulnerable code is present in our code base. For RHEL-9, DHCP uses the vulnerable BIND 9 libraries (bind-9.11.14) for some services. Hence, it is affected as well. Authoritative - Only BIND 9 servers are not vulnerable to this flaw.
Red Hat mitigation
If applicable, modify your configuration to either remove all forwarding or all possibility of recursion. Depending on your use case, it may be possible to use other zone types to replace forward zones.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:S/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (19 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 3.36% (0.03357) | 88.31th | v5 (v2026.06.15) |
| Jun 15, 2026 | 3.25% (0.03250) | 86.67th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.06% (0.00060) | 15.84th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.17% (0.00173) | 55.76th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.17% (0.00173) | 54.38th | v3 (v2023.03.01) |
| Jul 23, 2023 | 0.37% (0.00374) | 69.08th | v3 (v2023.03.01) |
| Jun 28, 2023 | 0.37% (0.00366) | 68.54th | v3 (v2023.03.01) |
| May 8, 2023 | 0.34% (0.00344) | 67.23th | v3 (v2023.03.01) |
| Mar 30, 2023 | 0.31% (0.00309) | 65.35th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.19% (0.00188) | 54.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.81% (0.02812) | 83.12th | v2 (v2022.01.01) |
| Nov 29, 2022 | 2.81% (0.02812) | 82.65th | v2 (v2022.01.01) |
| Oct 31, 2022 | 3.36% (0.03358) | 83.91th | v2 (v2022.01.01) |
| Sep 14, 2022 | 2.60% (0.02596) | 81.29th | v2 (v2022.01.01) |
| Apr 29, 2022 | 1.77% (0.01769) | 74.66th | v2 (v2022.01.01) |
| Apr 9, 2022 | 1.63% (0.01626) | 73.85th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Mar 30, 2022 | 0.95% (0.00954) | 17.50th | v2 (v2022.01.01) |
| Mar 24, 2022 | 0.89% (0.00885) | 11.49th | v2 (v2022.01.01) |
References (15)
- https://access.redhat.com/security/cve/CVE-2021-25220 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2064512 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf PatchThird Party Advisory
- https://kb.isc.org/docs/CVE-2021-25220
- https://kb.isc.org/v1/docs/cve-2021-25220 MitigationVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2SXT7247QTKNBQ67MNRGZD23ADXU6E5U/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5VX3I2U3ICOIEI5Y7OYA6CHOLFMNH3YQ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/API7U5E7SX7BAAVFNW366FFJGD6NZZKV/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DE3UAVCPUMAKG27ZL5YXSP2C3RIOW3JZ/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NYD7US4HZRFUGAJ66ZTHFBYVP5N3OQBY/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-25220
- https://security.gentoo.org/glsa/202210-25 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20220408-0001/ Third Party Advisory
- https://supportportal.juniper.net/s/article/2022-10-Security-Bulletin-Junos-OS-SRX-Series-Cache-poisoning-vulnerability-in-BIND-used-by-DNS-Proxy-CVE-2021-25220?language=en_US
- https://www.cve.org/CVERecord?id=CVE-2021-25220
Change history (0)
No recorded changes yet.