Back

HIGH

Assertion failure when serving both stale cache data and authoritative zone content

Published Jul 23, 2024

Description

Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.

Affected products

Remediation

Vendor solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.28, 9.20.0, or 9.18.28-S1.

Red Hat statement

The discovered flaw in the BIND9 package is of high severity due to its dual impact on DNS server functionality and stability. The issue where client queries trigger the return of stale data undermines the integrity and reliability of DNS responses, potentially leading to incorrect or outdated information being served to clients. This can cause significant disruptions in services reliant on accurate DNS resolutions. Moreover, the assertion failure triggered by local lookups poses a critical threat, as it can crash the BIND server, resulting in a denial of service (DoS). Such an outage disrupts DNS operations, impacting network availability and access to internet services.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner isc
Published Jul 23, 2024
Updated Feb 13, 2025
Reserved Apr 23, 2024
CISA Vulnrichment
Updated Jul 23, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 23, 2024