Impact
An attacker can craft DNS responses containing multiple identical singleton RDATA records, such as duplicate SOA records. When these duplicates are processed by the resolver, the record is appended to the in-memory RDATA set, increasing memory consumption in the negative cache. This can lead to excessive memory usage and potential denial of service if the attacker repeats the action.
Affected Systems
ISC BIND 9 implementations from version 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and the corresponding security‑patched releases 9.11.3‑S1 through 9.18.50‑S1 and 9.20.9‑S1 through 9.20.27‑S1. Any system running these versions of ISC BIND 9 on any platform is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires network access to the named service and the ability to send crafted responses; an attacker could trigger repeated cache growth leading to memory exhaustion, potentially disrupting DNS service availability.
OpenCVE Enrichment
Debian DSA