Related Vulnerabilities: CVE-2018-5736  

An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession.

Severity Medium

Remote Yes

Type Denial of service

Description

An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession.

AVG-706 bind 9.12.1-1 9.12.1.P2-1 Medium Fixed

20 May 2018 ASA-201805-20 AVG-706 bind Medium denial of service

https://kb.isc.org/article/AA-01602/74/CVE-2018-5736

Workaround:

For servers which must receive notifies to keep slave zone contents current, no complete workarounds are known although restricting BIND to only accept NOTIFY messages from authorized sources can greatly mitigate the risk of attack.