Impact
An attacker who crafts a DNS query name long enough to trigger a NAMETOOLONG error in RPZ processing can defeat the wildcard CNAME RPZ policy, effectively bypassing the intended DNS policy. The flaw originates from an improper handling of the error condition, which may also cause the BIND 9 process to exit unexpectedly, leading to a denial of DNS service for clients. This weakness is identified as CWE‑790, a race condition or logic error that allows simultaneous state and error handling paths to be exploited.
Affected Systems
The vulnerability is present in ISC BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and the corresponding –S1 releases 9.16.8‑S1 through 9.18.50‑S1 and 9.20.9‑S1 through 9.20.24‑S1. Updated releases such as 9.20.26, 9.21.24, and 9.20.26‑S1 contain the fix.
Risk and Exploitability
Based on the description, the attack vector is a network‑based attack requiring delivery of a crafted DNS query with an extremely long name to trigger the NAMETOOLONG error. The CVSS score of 7.5 indicates a high severity. The EPSS score of < 1 % indicates that exploitation is unlikely in the wild, and the vulnerability is not listed in CISA KEV. Successful exploitation would allow the resolver to bypass its wildcard CNAME RPZ rule and could cause an unexpected exit of the BIND 9 software, disrupting DNS service availability.
OpenCVE Enrichment
Debian DLA
Debian DSA