CVE-2021-25219 - CVE House
Back to Database
Status published Medium CVE-2021-25219

Lame cache can be abused to severely degrade resolver performance

Vulnerability Description

In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25219

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • ISC would like to thank Kishore Kumar Kothapalli of Infoblox for bringing this vulnerability to our attention.

Affected Vendor

Affected Software

BIND9
Vulnerable Versions:
Open Source Branches 9.3 through 9.11 9.3.0 through versions before 9.11.36, Open Source Branches 9.12 through 9.16 9.12.0 through versions before 9.16.22, Supported Preview Branches 9.9-S through 9.11-S 9.9.3-S1 through versions before 9.11.36-S1, Supported Preview Branch 9.16-S 9.16.8-S1 through versions before 9.16.22-S1, Development Branch 9.17 9.17.0 through versions before 9.17.19

Timeline

Official Publish: October 27th, 2021
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.