In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published: 2021-10-27T21:10:10.088929Z

Updated: 2024-09-16T17:33:38.865Z

Reserved: 2021-01-15T00:00:00

Link: CVE-2021-25219

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-27T21:15:07.613

Modified: 2023-11-07T03:31:25.127

Link: CVE-2021-25219

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-10-27T00:00:00Z

Links: CVE-2021-25219 - Bugzilla