Impact
A BIND 9 resolver may abort with an unexpected program exit when it receives a DNSSEC-signed authoritative zone that replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC record at the same owner name. This flaw, identified as CWE‑617, results in a crash that can be exploited to deny service to the resolver.
Affected Systems
Affected products are ISC BIND 9. Vulnerable releases include 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, as well as the corresponding signed releases 9.11.3‑S1 to 9.18.50‑S1 and 9.20.9‑S1 to 9.20.27‑S1.
Risk and Exploitability
The CVSS score of 7.5 illustrates a high impact on availability, while the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog and no public exploits are known. Based on the description, it is inferred that an attacker can trigger the crash by serving crafted responses from a malicious authoritative server over the network, requiring control of zone data rather than privileged local access. No workarounds are known, so mitigation relies solely on applying the vendor patch.
OpenCVE Enrichment
Debian DSA