Impact
A resolver that has cached a tree of SVCB/HTTPS AliasMode records may spend disproportionate CPU time constructing a response when queried for the root of that tree. The result is a denial‑of‑service condition affecting DNS resolution and potentially disrupting dependent services, but it does not expose confidentiality or integrity of data. The weakness corresponds to CWE-1050 and CWE-606.
Affected Systems
The vulnerability affects ISC BIND 9 products. Versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, as well as the corresponding –S1 maintenance releases, are impacted.
Risk and Exploitability
The CVSS score of 7.5 rates this as a high‑severity availability issue, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. The likely attack vector is a remote DNS query against a resolver that has already cached a large SVCB/HTTPS AliasMode tree; the attacker simply issues a query for the tree root to trigger the excessive CPU consumption. No privileged access or specific network configuration is required beyond obtaining the resolver’s public DNS service. The vulnerability is therefore exploitable on any public‑facing BIND 9 instance that handles SVCB/HTTPS AliasMode records.
OpenCVE Enrichment
Debian DSA