CVE-2021-25218
A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In BIND 9.16.19, 9.17.16. Also, version 9.16.19-S1 of BIND Supported Preview Edition When a vulnerable version of named receives a query under the circumstances described above, the named process will terminate due to a failed assertion check. The vulnerability affects only BIND 9 releases 9.16.19, 9.17.16, and release 9.16.19-S1 of the BIND Supported Preview Edition.
En BIND versiones 9.16.19, 9.17.16. Además, la versión 9.16.19-S1 de BIND Supported Preview Edition. Cuando una versión vulnerable de named recibe una consulta en las circunstancias descritas anteriormente, el proceso named terminará debido a una comprobación de aserción fallida. La vulnerabilidad sólo afecta a versiones 9.16.19, 9.17.16 y 9.16.19-S1 de BIND Supported Preview Edition.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-15 CVE Reserved
- 2021-08-18 CVE Published
- 2024-05-03 EPSS Updated
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-617: Reachable Assertion
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20210909-0002 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://kb.isc.org/v1/docs/cve-2021-25218 | 2024-09-17 |
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2021/08/18/3 | 2023-11-07 | |
http://www.openwall.com/lists/oss-security/2021/08/20/2 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.16.19 Search vendor "Isc" for product "Bind" and version "9.16.19" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.17.16 Search vendor "Isc" for product "Bind" and version "9.17.16" | - |
Affected
| ||||||
Isc Search vendor "Isc" | Bind Search vendor "Isc" for product "Bind" | 9.17.16 Search vendor "Isc" for product "Bind" and version "9.17.16" | s1, supported_preview |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
|