CVE-2021-25215 is a denial-of-service vulnerability affecting multiple versions of BIND 9, including those from ISC, Debian, Fedora, NetApp, Oracle, and Siemens. An unauthenticated attacker can remotely trigger a failed assertion check in the named process by sending a specially crafted query, causing the DNS server to terminate. This vulnerability has a CVSS score of 7.5 (High) due to its remote attack vector, low attack complexity, and high impact on availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.11.31CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.12.0, < 9.16.15CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.17.0, < 9.17.12CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-25215
May 11, 2021bind: An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
Apr 28, 2021An assertion check can fail while answering queries for DNAME records that require the DNAME to be processed to resolve itself
Apr 13, 2021