Back

HIGH

BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly

Published Sep 21, 2022

Description

By sending specific queries to the resolver, an attacker can cause named to crash.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND: BIND 9.16.33, BIND 9.18.7, BIND 9.19.5, or for BIND Supported Preview Edition (a special feature preview branch of BIND provided to eligible ISC support customers): BIND 9.16.33-S1.

Red Hat statement

This issue affects versions 9.16.14 and higher of the Bind package. Therefore Red Hat Enterprise Linux 6 and 7 are not impacted.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Sep 21, 2022
Updated Sep 17, 2024
Reserved Sep 1, 2022
CISA Vulnrichment
Updated Jun 26, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 21, 2022