Impact
According to the CVE description, if a provably insecure domain is covered by both NSEC and NSEC3 records at the parent zone, and an RRSIG exists for only one of those records, BIND 9 may terminate unexpectedly during zone validation. The crash is caused by an assertion failure, leading to a denial of service for DNS queries that trigger the validation path. This vulnerability is identified as CWE-617, representing unchecked input validation as justified by the assertion failure described in the CVE text.
Affected Systems
All ISC BIND 9 releases from 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, and 9.21.0 through 9.21.23, as well as the corresponding security‑patched point releases 9.11.3‑S1 through 9.18.50‑S1 and 9.20.9‑S1 through 9.20.24‑S1, are affected when both NSEC and NSEC3 coexist at the parent for an insecure domain.
Risk and Exploitability
Based on the description, the likely attack vector is DNS queries that trigger zone validation. The CVSS score of 7.5 indicates a moderate to high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Attackers are likely to exploit the flaw by issuing DNS queries that force the server to validate a zone containing conflicting NSEC and NSEC3 records. If successful, the BIND server will crash, resulting in temporary loss of availability for the affected zones and potentially broader DNS disruptions.
OpenCVE Enrichment
Debian DLA
Debian DSA