Impact
An attacker may cause a named resolver to abort by exploiting a use‑after‑free bug in the QPCache NOQNAME code. The bug is triggered when the resolver receives multiple DNSSEC‑signed queries from an attacker‑controlled authoritative server, and the responses arrive in a precise order and timing. When the conditions are met the resolver dereferences freed memory, crashes, and stops accepting further queries, leading to a denial of service for any client relying on that resolver.
Affected Systems
ISC BIND 9 is affected. Vulnerable versions include all releases from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.27‑S1.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score below 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires control of an authoritative server and precise timing of responses, it is not trivial to exploit in the wild. However, the crash can abruptly terminate the recursive resolver, disrupting services that depend on DNS lookups.
OpenCVE Enrichment
Debian DSA