Impact
If a BIND instance loads a configuration file without the required global options block, a malicious TKEY query may trigger an assertion failure that brings the server to an unexpected exit. This results in a denial‑of‑service condition and may cause the DNS service to become unavailable to clients. The weakness is reflected in CWE‑617.
Affected Systems
The flaw affects all BIND 9 releases from 9.20.0 through 9.20.27, from 9.21.0 through 9.21.25, and from the short‑lived 9.20.9‑S1 through 9.20.27‑S1. All installations that use ISC BIND 9 and rely on the default named.conf configuration without an options stanza are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity, while the EPSS of less than 1 % signals a very low but non‑zero likelihood of exploitation in the wild; the vulnerability is currently not listed in CISA’s KEV catalog. An attacker simply needs to send a crafted TKEY query to the exposed BIND server; no privileged access or complex setup is required. Because the problem is triggered by a missing configuration element, it can be rendered inoperable with a relatively simple patch or configuration change.
OpenCVE Enrichment
Debian DSA