Impact
The flaw occurs when a BIND resolver processes an SVCB/HTTPS AliasMode record that references fourteen or more SVCB/HTTPS ServiceMode records. The resolver fails to release internal memory and a reference cache, causing a memory leak that can grow with repeated lookups. Over time the resolver runs out of available resources, any new recursive lookup attempts fail, and DNS service becomes unavailable for clients.
Affected Systems
The vulnerability impacts ISC BIND 9 in several released branches. Affected versions include 9.18.0 to 9.18.50, 9.20.0 to 9.20.27, 9.21.0 to 9.21.25, the 9.18.11-S1 through 9.18.50-S1 maintenance updates, and the 9.20.9-S1 through 9.20.27-S1 S1 releases. Systems running these binaries should verify their current release against the patched versions 9.20.29, 9.21.26, or 9.20.29‑S1.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high overall risk. The EPSS score is below 1%, suggesting a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can trigger the condition by sending crafted DNS responses or by manipulating zone data that forces the resolver to retrieve many ServiceMode records. Based on the description, it is also inferred that the attack path is remote, as the resolver accepts DNS traffic from the network. The combination of high impact and low exploitation likelihood places the threat at moderate risk for environments that expose recursive resolution to potentially untrusted queries.
OpenCVE Enrichment
Debian DSA