In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2647-1 bind9 security update
Debian DSA Debian DSA DSA-4909-1 bind9 security update
EUVD EUVD EUVD-2021-12126 In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.
Ubuntu USN Ubuntu USN USN-4929-1 Bind vulnerabilities
Ubuntu USN Ubuntu USN USN-7739-1 Bind vulnerabilities
Fixes

Solution

Upgrade to the patched release most closely related to your current version of BIND: BIND 9.11.31 BIND 9.16.15 BIND 9.17.12 BIND Supported Preview Edition is a special feature preview branch of BIND provided to eligible ISC support customers. BIND 9.11.31-S1 BIND 9.16.15-S1


Workaround

No workarounds known.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2024-09-16T22:02:24.791Z

Reserved: 2021-01-15T00:00:00

Link: CVE-2021-25215

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-29T01:15:08.013

Modified: 2024-11-21T05:54:33.650

Link: CVE-2021-25215

cve-icon Redhat

Severity : Important

Publid Date: 2021-04-28T00:00:00Z

Links: CVE-2021-25215 - Bugzilla

cve-icon OpenCVE Enrichment

No data.