The BIND resolver accepts validly-signed NSEC records where the Next Domain Name field points outside the signers zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.
The product does not properly verify that the source of data or communication is valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | RedHat | bind9.16-32:9.16.23-0.22.el8_10.12 | * |
| Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-16.el8_10.14 | * |
| Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-16.el8_10.14 | * |
| Red Hat Enterprise Linux 9 | RedHat | bind-32:9.16.23-40.el9_8.8 | * |
| Red Hat Hardened Images | RedHat | bind-main-9.20.26-0.1.hum1 | * |