Back

HIGH

bind: Lookups involving a DNAME could trigger an assertion failure when 'synth-from-dnssec' was enabled (which is the default)

Published Mar 23, 2022

Description

Versions affected: BIND 9.18.0 When a vulnerable version of named receives a series of specific queries, the named process will eventually terminate due to a failed assertion check.

Affected products

Remediation

Vendor solution

Users of BIND 9.18.0 should upgrade to BIND 9.18.1

Red Hat statement

The vulnerability affects BIND resolvers running 9.18.0 with both dnssec-validation and synth-from-dnssec enabled. (Note that dnssec-validation auto; is the default setting unless configured otherwise in named.conf and that enabling dnssec-validation automatically enables synth-from-dnssec unless explicitly disabled) This flaw only affects BIND-9.18.0, whereas Red Hat ships BIND-9.16 and lower versions. Therefore, versions of BIND shipped with Red Hat Products are not affected by this flaw.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Mar 23, 2022
Updated Sep 17, 2024
Reserved Feb 16, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 16, 2022