Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-2911

25
FAUCET Score

CVE-2023-2911 is a denial-of-service vulnerability affecting specific versions of BIND 9 resolvers, including those from Debian, Fedora Project, ISC, and NetApp. When configured with "stale-answer-enable yes;" and "stale-answer-client-timeout 0;", reaching the "recursive-clients" quota can lead to a stack overflow and unexpected termination of the named process. This vulnerability carries a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity, resulting in a high impact on availability. There is no user interaction required for a successful attack. Currently, there is no known active exploitation, nor is public exploit code available in Metasploit, Nuclei, or ExploitDB. While the vulnerability has garnered some community discussion and media coverage, it is not listed on the CISA KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.16.33, <= 9.16.41CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
>= 9.16.33, <= 9.16.41CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:supported_preview:*:*:*
>= 9.18.7, <= 9.18.15CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
>= 9.18.11, <= 9.18.15CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:supported_preview:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.45%
Probability of exploitation in next 30 days
EPSS Percentile
82.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0245 is in the 69th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

consensyspatch availablevia llm_extracted
Fixed in: 9.18.16-S1
View patch
microsoftpatch availablevia msrc
Product: cbl2 bind 9.16.44-1 on CBL Mariner 2.0Fixed in: 9.16.44-1
nessuspatch availablevia llm_extracted
Fixed in: 9.18.16-S1
View patch
alistgovendor investigatingvia llm_extracted
View patch

Vendor Advisories (5)

redhatCVE-2023-2911Moderate

bind: Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0

Jun 21, 2023
microsoft2023-Jun/CVE-2023-2911Important

Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0

Jun 13, 2023
nessusllm-nessus-e77cedcc23e10113
alistgollm-alistgo-f39f878ee5a7b26c

Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0

consensysllm-consensys-e029dc18577049c9

References

kb.isc.org / docs/cve-2023-2911
Vendor Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/SEFCEVCTYEMKTWA7V7EYPI5YQQ4JWDLI
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/U3K6AJK7RRSR53HRF5GGKPA6PDUDWOD2
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20230703-0010
Third Party Advisory
debian.org / security/2023/dsa-5439
Third Party Advisory
openwall.com / lists/oss-security/2023/06/21/6
Mailing ListPatchThird Party Advisory