Back

HIGH

named configured to answer from stale cache may terminate unexpectedly while processing RRSIG queries

Published Jan 25, 2023

Description

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.37, 9.18.11, 9.19.9, or 9.16.37-S1.

Red Hat statement

The flaw exists in the implementation of the stale-answer-client-timeout option, which was first effectively introduced in bind 9.16.12.

Red Hat mitigation

Setting stale-answer-client-timeout to 0 or to off/disabled will prevent BIND from crashing due to this issue.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jan 25, 2023
Updated Apr 1, 2025
Reserved Oct 28, 2022
CISA Vulnrichment
Updated Apr 1, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 25, 2023