Impact
A BIND recursive resolver can consume excessive CPU and memory when it receives many invalid DNSSEC records that match a specific pattern. The flaw is a resource management weakness (CWE-407) that is amplified by improper memory allocation (CWE-770). If exploited, the resolver may become unresponsive because the system runs out of space or processing power to handle legitimate queries.
Affected Systems
ISC BIND 9 versions from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, the corresponding -S1 releases, and 9.20.9-S1 through 9.20.27-S1 are affected. Any environment running these releases is at risk if it operates as a recursive resolver.
Risk and Exploitability
The likely attack vector is sending crafted DNS responses that contain many invalid DNSSEC records to the resolver. The CVSS score of 5.3 indicates a moderate severity. With an EPSS score of less than 1% and no listing in the CISA KEV catalog, widespread exploitation is currently unlikely, but the attack surface exists because the vulnerability is triggered by ordinary DNS traffic routed to the server. An attacker can send crafted DNS responses that contain a large number of invalid DNSSEC records; if the resolver processes them, the local resources may be exhausted, leading to a denial-of-service of the DNS service. The vulnerability is most likely exploitable over the network by any party that can manipulate upstream responses or control DNS traffic destined for the server.
OpenCVE Enrichment
Debian DSA