CVE-2021-25218

Related Vulnerabilities: CVE-2021-25218  

In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion check. The vulnerability affects only BIND 9 releases 9.16.19, 9.17.16, and release 9.16.19-S1 of the BIND Supported Preview Edition.

Description

The MITRE CVE dictionary describes this issue as:

In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion check. The vulnerability affects only BIND 9 releases 9.16.19, 9.17.16, and release 9.16.19-S1 of the BIND Supported Preview Edition.

Additional Information

  • Bugzilla 1995312: CVE-2021-25218 bind: a too-strict assertion check could be triggered when responses require UDP fragmentation if RRL is in use
  • CWE-617: Reachable Assertion
  • FAQ: Frequently asked questions about CVE-2021-25218