Impact
The vulnerability in the ISC BIND 9 resolver allows the system to accept validly‑signed NSEC records where the “Next Domain Name” field references a name outside the zone that issued the signature. This flaw bypasses the standard DNSSEC validation that should ensure an NSEC record belongs to the owner zone, potentially allowing an attacker to cause the resolver to treat an out‑of‑zone NSEC as legitimate. The weakness is recorded as external control of system parameters, matching CWE‑346, and could undermine the confidentiality, integrity, or availability of DNS services that rely on strict DNSSEC enforcement.
Affected Systems
The affected products are ISC BIND 9 releases covering 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and the corresponding –S1 builds 9.11.3‑S1 to 9.18.50‑S1 and 9.20.9‑S1 to 9.20.24‑S1.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity. The EPSS score is reported as < 1% and the vulnerability is not listed in the CISA KEV catalog. It is inferred that an attacker could manipulate DNS queries sent to a vulnerable resolver to retrieve out‑of‑zone NSEC records, thereby subverting DNSSEC validation checks. This would allow remote compromise of DNS responses that depend on the resolver’s validation behavior.
OpenCVE Enrichment
Debian DLA
Debian DSA