Impact
A flaw in the dns_ncache_add function of ISC BIND 9 arises when an authoritative server returns a negative answer that is exactly 65536 bytes. The 16-bit length field in the cache entry is truncated, creating a cache entry of size zero but recorded as negative. When this corrupt entry is later read, the named daemon aborts. The result is a denial of service that disrupts name resolution services.
Affected Systems
The vulnerability affects ISC BIND 9 versions from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, as well as the corresponding -S1 branch releases (9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.27-S1). Operators running any of these revisions on authoritative, stub, or recursive name servers are potentially impacted, especially if they depend on upstream authoritative servers that could be controlled by an adversary.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, but the EPSS score of less than 1% signals that large-scale exploitation is currently uncommon. The vulnerability is not listed in CISA’s KEV catalog, further reflecting a low probability of targeted attacks. Exploitation requires an attacker to control an authoritative server or otherwise deliver a crafted negative DNS response; thus the attack vector is remote and would typically involve spoofing or poisoning a DNS path to influence the resolver in danger. Because the denial of service manifests as a crash in the named process, the impact is limited to availability, but repeated crashes could lead to a broader outage of DNS resolution services.
OpenCVE Enrichment
Debian DSA