Impact
This vulnerability allows an attacker to craft a malformed DNS zone that contains an NS or DNAME node positioned above the zone origin. When named loads such a zone, it interprets the node as a zone cut, effectively truncating the zone at that point. As a result, queries for names that are actually inside the intended zone lose authoritative status and receive answers that originate from the injected zone cut. On a server providing recursion, named will follow this locally generated cut, cache the attacker’s data, and serve it for queries outside the configured zone. This can lead to DNS data spoofing and potentially redirect or downgrade DNS traffic for domains that rely on the server’s recursion.
Affected Systems
The flaw affects ISC BIND 9 versions from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.27‑S1, which includes all actively maintained releases up to the latest Stable‑S1 platforms. The affected product is the ISC BIND 9 authoritative DNS server.
Risk and Exploitability
The CVSS base score of 5.8 indicates moderate severity; the EPSS score of less than 1% suggests a low probability that the vulnerability will be exploited in the near term. It is not registered in the CISA KEV catalog today. An attacker would need the ability to introduce a crafted zone file—through zone transfer, the web‑based administration interface, or direct file editing on the server—and then trigger a reload of the zone. Once the malformed zone is present, the effect lasts until the zone file is corrected or the server is restarted. Because DNS data is being overwritten for all domains under the cut, affected clients could receive false information, leading to redirection or denial of service against domains that were not intended to be controlled by the attacker.
OpenCVE Enrichment