Impact
The flaw causes the named daemon to terminate unexpectedly when an authoritative server responds to a CNAME or DNAME query in a delayed fashion after sending an A record. The delayed or self-referential CNAME, combined with a prior A response, triggers a crash that stops the DNS resolver service. The failure is deterministic for the described query patterns.
Affected Systems
International Systems Consortium BIND 9 is impacted. The vulnerability exists in versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.24‑S1. Any installation running these releases that processes standard DNS queries can be affected.
Risk and Exploitability
The CVSS score of 7.5 rates this as high severity, while an EPSS score below 1% indicates a very low current exploitation probability. The vulnerability is not listed in CISA KEV. Based on the description, attackers could trigger the failure by sending crafted DNS queries or manipulating authoritative responses; it is inferred that no privileged access is required. The resulting denial of service can disrupt all clients relying on the affected DNS server.
OpenCVE Enrichment
Debian DLA
Debian DSA