Impact
An attacker can respond to a DNS query using an RRSIG that contains fewer labels than the zone in which the signature is embedded. When the resolver has its synth-from-dnssec option set to yes (the default), the resolver attempts to synthesize a record and produces a wildcard name for the zone that is shorter than the attacker’s zone. This synthesis can inject counterfeit data into the resolver’s cache, leading to a clear breach of DNS integrity.
Affected Systems
ISC BIND 9 software is affected, specifically all releases from 9.11.0 up to 9.18.50, 9.20.0 up to 9.20.24, 9.21.0 up to 9.21.23 and their corresponding security‑patch releases 9.11.3‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.24‑S1. Any deployment of these BIND versions that uses synth-from-dnssec does not implement the necessary validation logic to prevent the wildcard synthesis induced by a rogue RRSIG.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is classified as high severity. The EPSS score is < 1%, indicating a very low exploitation probability, but the flaw is not listed in CISA KEV, indicating no publicly known active exploitation as of this analysis. The attack requires that an attacker control a zone that can respond with an RRSIG of lower label count and that the target resolver accepts the query and has synth-from-dnssec enabled. Under those conditions the attacker can achieve cache poisoning and subvert normal domain resolution.
OpenCVE Enrichment
Debian DLA
Debian DSA