Impact
A use‑after‑free flaw in the query_addnoqnameproof() function, triggered via the DNS64 filter64 path, causes the named daemon to terminate unexpectedly when it receives a maliciously malformed answer from an authoritative server. The resulting crash interrupts DNS resolution services, effectively denying the resolver to clients until the process is restarted. The vulnerability is rooted in improper memory handling (CWE-416) and a lack of input validation (CWE-617).
Affected Systems
ISC BIND 9 is affected. Specifically, vulnerable releases include versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, their -S1 variants, and 9.20.9-S1 through 9.20.27-S1. All configurations that enable the dns64 feature expose the resolver to this flaw.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at the time of this analysis. The flaw is not listed in the CISA KEV catalog, and no publicly documented exploits are known. Likely attack vectors involve an attacker controlling or compromising an authoritative server that returns a malformed response designed to trigger the use‑after‑free. The vulnerability requires that the resolver be actively processing queries via dns64, so it is most relevant to organizations running BIND with that feature enabled.
OpenCVE Enrichment
Debian DSA