CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
49.4%
If the recursive-clients
quota is reached on a BIND 9 resolver configured with both stale-answer-enable yes;
and stale-answer-client-timeout 0;
, a sequence of serve-stale-related lookups could cause named
to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33 through 9.16.41, 9.18.7 through 9.18.15, 9.16.33-S1 through 9.16.41-S1, and 9.18.11-S1 through 9.18.15-S1.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | bind9 | < 1:9.18.16-1~deb12u1 | bind9_1:9.18.16-1~deb12u1_all.deb |
Debian | 11 | all | bind9 | < 1:9.16.42-1~deb11u1 | bind9_1:9.16.42-1~deb11u1_all.deb |
Debian | 999 | all | bind9 | < 1:9.18.16-1 | bind9_1:9.18.16-1_all.deb |
Debian | 13 | all | bind9 | < 1:9.18.16-1 | bind9_1:9.18.16-1_all.deb |
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AI Score
Confidence
High
EPSS
Percentile
49.4%