Impact
A DNSSEC‑validating resolver can be forced to allocate memory far beyond the configured "max-cache-size" when an attacker sends validation queries at a rate faster than the resolver can process. This uncontrolled allocation leads to resource exhaustion, allowing the attacker to consume large amounts of system memory and potentially cause the resolver to degrade or become unavailable. The weakness represents a classic uncontrolled resource consumption flaw (CWE‑400) and a resource exhaustion leak (CWE‑770).
Affected Systems
The vulnerability impacts ISC BIND 9 resolvers across multiple major releases: 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and the corresponding security‑patched branches 9.11.3‑S1 through 9.18.50‑S1 and 9.20.9‑S1 through 9.20.24‑S1. Any installation of these version ranges is susceptible if the resolver is configured to perform DNSSEC validation.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high‑severity vulnerability, yet the EPSS score of < 1% indicates a low probability that it is actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be a network‑based scenario where an adversary submits a sustained stream of DNS queries to the resolver, overwhelming its validation process and triggering memory exhaustion.
OpenCVE Enrichment
Debian DLA
Debian DSA