Back

HIGH

Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution

Published Feb 13, 2024

Description

A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.16.48, 9.18.24, 9.19.21, 9.16.48-S1, or 9.18.24-S1.

Red Hat statement

The identified vulnerability in the BIND DNS server poses a important severity risk due to its potential to induce a Denial of Service (DoS) through a targeted exploitation of DNS64 functionality. Specifically, the flaw allows an attacker to send a crafted domain query that triggers a code assertion failure within the named process. This leads to a crash of the DNS server, disrupting its ability to resolve queries and maintain network operations. As a result, the DNS service becomes unavailable to legitimate users, impacting the integrity and availability of network services and potentially disrupting business operations or network communications. The exploitation of this vulnerability by an unauthenticated remote user underscores the urgent need for immediate patching and mitigation to safeguard DNS infrastructure against service outages.

Red Hat mitigation

This vulnerability can be mitigated by either disabled server-stale configuration, using both of the switches bellow in named configuration file: 1) set stale-cache-enable no; 2) set stale-answer-enable no; Alternatively, disable the DNS64 option. Both mitigations should make the affected code unreachable, making it impossible to an attacker to exploit this vulnerability.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Feb 13, 2024
Updated Mar 28, 2025
Reserved Oct 20, 2023
CISA Vulnrichment
Updated Feb 13, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 13, 2024