Impact
An attacker can cause the named DNS server to abort by sending a single DNS‑over‑HTTPS request that contains a cryptographically invalid SIG(0) record and then closing the transport connection. The flaw results in a crash that leads to denial of service. The weakness is due to a null pointer dereference (CWE‑476) and poor validation of external input (CWE‑617). No authentication is required and the vulnerability can be triggered with a single malformed packet.
Affected Systems
ISC BIND 9, specifically versions 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, and the release‑specific 9.20.9‑S1 through 9.20.27‑S1. All deployments of the named daemon that expose a DoH interface are potentially affected.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity of exposure. The EPSS score is 7%, signaling a moderate probability that exploitation may occur. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability from any remote network that can reach the DoH port; no authentication or prior access is required. A single malicious HTTPS query containing a malformed SIG(0) record is sufficient to trigger the crash.
OpenCVE Enrichment
Debian DSA