CVE-2021-25219 is a performance degradation vulnerability affecting various versions of BIND 9, including the Supported Preview Edition and development branches. It arises from a flaw in response processing when interacting with broken authoritative servers, leading to an almost infinitely growing lame cache. This can cause significant delays in client query processing for affected products from vendors like Debian, Fedora, ISC, NetApp, Oracle, and Siemens. The vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with low complexity and no user interaction required, resulting in a low impact on availability. There is no known impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.3.0, < 9.11.36CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.12.0, < 9.16.22CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.17.0, < 9.17.19CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
9.9.3CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:* | ||
9.9.12CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.