CVE-2021-25215: An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.
Other sources
ISC BIND is vulnerable to a denial of service, caused by an assertion failure while answering queries for DNAME records. By sending a query for DNAME records, an attacker could exploit this vulnerability to trigger a failed assertion check and terminate the named process.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID of this ISC BIND vulnerability?
The vulnerability ID of this ISC BIND vulnerability is CVE-2021-25215.
What is the severity level of CVE-2021-25215?
CVE-2021-25215 has a severity level of high.
Which versions of BIND are affected by CVE-2021-25215?
Versions 9.0.0 to 9.11.29, 9.12.0 to 9.16.13, 9.9.3-S1 to 9.11.29-S1, 9.16.8-S1 to 9.16.13-S1, and 9.17.0 to 9.17.11 of BIND are affected by CVE-2021-25215.
How can I fix the CVE-2021-25215 vulnerability?
To fix the CVE-2021-25215 vulnerability, upgrade to BIND version 9.11.5.P4+dfsg-5.1+deb10u7, 9.11.5.P4+dfsg-5.1+deb10u9, 9.16.44-1~deb11u1, 9.18.19-1~deb12u1, or 9.19.17-1.
Are there any references I can check for more information about CVE-2021-25215?
Yes, you can check the following references for more information about CVE-2021-25215: [1](http://www.openwall.com/lists/oss-security/2021/04/29/1), [2](http://www.openwall.com/lists/oss-security/2021/04/29/2), [3](http://www.openwall.com/lists/oss-security/2021/04/29/3).