BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Directory integrated DNS deployments and/or Kerberos-secured DNS environments. This issue affects BIND 9 versions 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.
The product does not properly maintain a reference to a resource that has been allocated, which prevents the resource from being reclaimed.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bind | Isc | 9.0.0 (including) | 9.16.50 (including) |
| Bind | Isc | 9.18.0 (including) | 9.18.49 (excluding) |
| Bind | Isc | 9.20.0 (including) | 9.20.23 (excluding) |
| Bind | Isc | 9.21.0 (including) | 9.21.22 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | bind-32:9.18.33-15.el10_2.2 | * |
| Red Hat Enterprise Linux 8 | RedHat | bind9.16-32:9.16.23-0.22.el8_10.6 | * |
| Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-16.el8_10.8 | * |
| Red Hat Enterprise Linux 8 | RedHat | bind-32:9.11.36-16.el8_10.8 | * |
| Red Hat Enterprise Linux 9 | RedHat | bind-32:9.16.23-40.el9_8.2 | * |
| Red Hat Enterprise Linux 9 | RedHat | bind9.18-32:9.18.29-14.el9_8.2 | * |
| Red Hat Hardened Images | RedHat | bind-main-9.18.49-1.hum1 | * |
| Bind9 | Ubuntu | devel | * |
| Bind9 | Ubuntu | esm-infra/xenial | * |
| Bind9 | Ubuntu | jammy | * |
| Bind9 | Ubuntu | noble | * |
| Bind9 | Ubuntu | questing | * |
| Bind9 | Ubuntu | resolute | * |
| Bind9 | Ubuntu | upstream | * |
| Bind9-libs | Ubuntu | esm-infra/focal | * |
| Bind9-libs | Ubuntu | jammy | * |
| Bind9-libs | Ubuntu | upstream | * |