Reachable Assertion in ISC BIND - CVE-2021-25214
Published: April 29, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion when pressing IXFR queries. An IXFR stream containing SOA records with an owner name other than the transferred zone's apex may cause the receiving named
server to inadvertently remove the SOA record for the zone in question
from the zone database. This leads to an assertion failure when the next
SOA refresh query for that zone is made. When a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.
Affected software
Arch Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Anolis OS
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
CentOS
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
HPE Helion Openstack
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
SUSE Linux Enterprise Debuginfo
SUSE Linux Enterprise Point of Sale
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
openEuler
Fedora
BIG-IP
IBM Integrated Analytics System
Cloud Pak for Security (CP4S)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
BIG-IQ Centralized Management
IBM Hardware Management Console
bind9 (Debian package)
dnsperf
dhcp
dhcp-devel
dhcp-debuginfo
dhcp-debugsource
dhcp-help
bind9 (Ubuntu package)
bind-doc
bind-libs
bind-utils
bind-libs-32bit
bind-devel
bind-debuginfo
bind-debugsource
bind-chrootenv
bind
bind-utils-debuginfo
bind-libs-debuginfo
bind-libs-debuginfo-32bit
bind-pkcs11
bind-lite-devel
bind-license
bind-libs-lite
bind-export-libs
bind-export-devel
bind-chroot
bind-pkcs11-devel
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
bind (Red Hat package) main
python3-bind
libirs161-debuginfo
liblwres161-debuginfo
liblwres161
python-bind
libisc1107-debuginfo-32bit
libisc1107-debuginfo
libisccc161
libisccc161-debuginfo
libisccfg163
libisccfg163-debuginfo
libisc1107
libisc1107-32bit
libirs161
libdns1110-debuginfo
libdns1110
libbind9-161-debuginfo
libbind9-161
libns1604-debuginfo
libdns1605
libns1604
libisccfg1600
libisccc1600-debuginfo
libisccc1600
libisc1606-debuginfo
libisc1606
libirs1601-debuginfo
libirs1601
libirs-devel
libdns1605-debuginfo
libisccfg1600-debuginfo
libbind9-1600-debuginfo
libbind9-1600
bind-dyndb-ldap
SINEC INS
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2021-25214
Cloud Pak for Security (CP4S) - update to 1.8.0.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.0.8
bind9 (Debian package) - update to 1:9.11.5.P4+dfsg-5.1+deb10u5
SINEC INS - update to 1.0.1.1
dnsperf - update to 2.3.4-6.fc32
dhcp - update to 4.4.2-8
dhcp-devel - update to 4.4.2-8
dhcp-debuginfo - update to 4.4.2-8
dhcp-debugsource - update to 4.4.2-8
dhcp-help - update to 4.4.2-8
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
IBM Hardware Management Console - addressed in versions 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc
bind9 (Ubuntu package) - addressed in versions 1:9.9.5.dfsg-3ubuntu0.19+esm13, 1:9.10.3.dfsg.P4-8ubuntu1.19, 1:9.11.3+dfsg-1ubuntu1.15, 1:9.16.1-0ubuntu2.8, 1:9.16.6-3ubuntu1.2, 1:9.16.8-1ubuntu3.1
bind-doc - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind-libs - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1
bind-utils - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind-libs-32bit - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1
bind-devel - addressed in versions 9.9.6P1-0.51.26.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind-debuginfo - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind-debugsource - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind-chrootenv - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind - addressed in versions 9.9.6P1-0.51.26.1, 9.9.9P1-63.25.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind-utils-debuginfo - addressed in versions 9.9.9P1-63.25.1, 9.11.22-3.34.1, 9.16.6-12.49.1, 9.16.6-22.7.1
bind-libs-debuginfo - update to 9.9.9P1-63.25.1
bind-libs-debuginfo-32bit - update to 9.9.9P1-63.25.1
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-license - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.26-4
bind (Red Hat package) main - addressed in versions 9.11.4-26.P2.el7_9.7, 9.11.26-6.el8
bind-debugsource - update to 9.11.21-6
python3-bind - update to 9.11.21-6
bind-export-devel - update to 9.11.21-6
bind-export-libs - update to 9.11.21-6
bind-libs - update to 9.11.21-6
bind-libs-lite - update to 9.11.21-6
bind-pkcs11-devel - update to 9.11.21-6
bind-utils - update to 9.11.21-6
bind-devel - update to 9.11.21-6
bind-pkcs11 - update to 9.11.21-6
bind-chroot - update to 9.11.21-6
bind-debuginfo - update to 9.11.21-6
bind - update to 9.11.21-6
libirs161-debuginfo - update to 9.11.22-3.34.1
liblwres161-debuginfo - update to 9.11.22-3.34.1
liblwres161 - update to 9.11.22-3.34.1
python-bind - update to 9.11.22-3.34.1
libisc1107-debuginfo-32bit - update to 9.11.22-3.34.1
libisc1107-debuginfo - update to 9.11.22-3.34.1
libisccc161 - update to 9.11.22-3.34.1
libisccc161-debuginfo - update to 9.11.22-3.34.1
libisccfg163 - update to 9.11.22-3.34.1
libisccfg163-debuginfo - update to 9.11.22-3.34.1
libisc1107 - update to 9.11.22-3.34.1
libisc1107-32bit - update to 9.11.22-3.34.1
libirs161 - update to 9.11.22-3.34.1
libdns1110-debuginfo - update to 9.11.22-3.34.1
libdns1110 - update to 9.11.22-3.34.1
libbind9-161-debuginfo - update to 9.11.22-3.34.1
libbind9-161 - update to 9.11.22-3.34.1
python3-bind - update to 9.11.26-4
bind - addressed in versions 9.11.31-1.fc32, 9.11.31-1.fc33, 9.16.15-1.fc34
python3-bind - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libns1604-debuginfo - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libdns1605 - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libns1604 - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libisccfg1600 - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libisccc1600-debuginfo - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libisccc1600 - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libisc1606-debuginfo - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libisc1606 - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libirs1601-debuginfo - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libirs1601 - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libirs-devel - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libdns1605-debuginfo - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
libbind9-1600 - addressed in versions 9.16.6-12.49.1, 9.16.6-22.7.1
bind-dyndb-ldap - addressed in versions 11.3-6.fc32, 11.3-7.fc33, 11.7-3.fc34
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Slackware Linux update for bind
- Arch Linux update for bind
- Debian update for bind9
- Denial of service in F5 BIG-IP BIND
- Red Hat Enterprise Linux 7 update for bind
- CentOS 7 update for bind
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in IBM Integrated Analytics System
- Multiple vulnerabilities in Siemens SINEC INS
- Denial of service in IBM Power HMC
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- Ubuntu update for bind9
- Multiple vulnerabilities in IBM Cloud Pak for Security
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for ISC BIND
- Red Hat Enterprise Linux 8 update for bind
- SUSE update for bind
- SUSE update for bind
- openEuler 20.03 LTS SP1 update for bind
- openEuler update for dhcp
- Fedora 34 update for bind, bind-dyndb-ldap
- Fedora 33 update for bind, bind-dyndb-ldap
- Fedora 32 update for bind, bind-dyndb-ldap, dnsperf
- Anolis OS update for bind (Anolis OS 8.4)
- Anolis OS update for bind
- Ubuntu update for bind9