Back

HIGH

named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries

Published Jan 25, 2023

Description

Processing of repeated responses to the same query, where both responses contain ECS pseudo-options, but where the first is broken in some way, can cause BIND to exit with an assertion failure.

'Broken' in this context is anything that would cause the resolver to reject the query response, such as a mismatch between query and answer name. This issue affects BIND 9 versions 9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.37-S1.

Red Hat statement

This issue only affects the special feature preview branch of bind. Bind packages shipped with Red Hat Enterprise Linux are not affected by this flaw.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jan 25, 2023
Updated Apr 1, 2025
Reserved Oct 13, 2022
CISA Vulnrichment
Updated Apr 1, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 25, 2023