Reliance on Reverse DNS Resolution for a Security-Critical Action in ISC BIND - CVE-2021-25220
Published: March 17, 2022 / Updated: October 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to poison DNS cache.
The vulnerability exists due to an error in DNS forwarder implementation. When using forwarders, bogus NS records supplied by, or via, those forwarders may be cached and used by named if it needs to recurse for any reason, causing it to obtain and pass on potentially incorrect answers. The cache could become poisoned with incorrect records leading to
queries being made to the wrong servers, which might also result in
false information being returned to clients.
Affected software
Oracle Linux
Gentoo Linux
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Enterprise Storage
Red Hat Enterprise Linux Server
CentOS
Anolis OS
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power, big endian
IBM AIX
IBM i
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat Enterprise Linux for x86_64
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
Slackware Linux
Ubuntu
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
Junos OS
openEuler
Fedora
IBM VIOS
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
bind9 (Debian package)
python-sss-murmur
libsss_sudo
python-sss
python-libsss_nss_idmap
python-libipa_hbac
libsss_simpleifp-devel
libsss_simpleifp
libsss_nss_idmap-devel
libsss_nss_idmap
libsss_idmap-devel
sssd-ipa
libsss_idmap
libsss_certmap-devel
sssd-dbus
sssd-common-pac
libipa_hbac
libipa_hbac-devel
libsss_autofs
libsss_certmap
sssd-polkit-rules
sssd-common
sssd-client
sssd-ad
sssd
python-sssdconfig
sssd-winbind-idmap
sssd-tools
sssd-proxy
sssd-libwbclient-devel
sssd-libwbclient
sssd-kcm
sssd-krb5
sssd-krb5-common
sssd-ldap
dhcp (Red Hat package)
dhcp
dhcp-devel
dhcp-debuginfo
dhcp-debugsource
dhcp-help
bind (Red Hat package) main
bind-doc
bind
bind-chrootenv
bind-debuginfo
bind-debugsource
bind-libs-32bit
bind-libs
bind-libs-debuginfo-32bit
bind-libs-debuginfo
bind-utils
bind-utils-debuginfo
bind9 (Ubuntu package)
bind-lite-devel
bind-chroot
bind-devel
bind-export-devel
bind-export-libs
bind-libs-lite
bind-license
bind-pkcs11
bind-pkcs11-devel
bind-pkcs11-libs
bind-pkcs11-utils
bind-sdb
bind-sdb-chroot
libirs161
libbind9-161
libbind9-161-debuginfo
libdns1110
libdns1110-debuginfo
libisccc161-debuginfo
libirs161-debuginfo
libisc1107-32bit
libisc1107
libisc1107-debuginfo-32bit
libisc1107-debuginfo
libisccc161
python-bind
liblwres161-debuginfo
liblwres161
libisccfg163-debuginfo
libisccfg163
libirs-devel
libns1604
libns1604-debuginfo
python3-bind
libisccfg1600
libisccc1600-debuginfo
libisccc1600
libisc1606-debuginfo
libisc1606
libirs1601-debuginfo
libirs1601
libdns1605-debuginfo
libisccfg1600-debuginfo
libdns1605
libbind9-1600-debuginfo
libbind9-1600
bind9.16 (Red Hat package)
bind9.16-libs
bind9.16-utils
bind9.16-doc
bind9.16-license
python3-bind9.16
bind9.16-chroot
bind9.16
bind9.16-dnssec-utils
net-dns/bind-tools
net-dns/bind
bind-dyndb-ldap
Oracle Communications Diameter Signaling Router
Netcool Operations Insight
Ansible Automation Platform
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
HP-UX BIND
IBM Cloud Pak for Watson AIOps
EMC ECS
Robotic Process Automation for Cloud Pak
SINEC INS
Red Hat OpenShift GitOps
OpenShift Service Mesh
OpenShift Virtualization
Red Hat OpenShift Container Platform
IBM Qradar SIEM
Juniper Junos Space
How to mitigate CVE-2021-25220
bind9 (Debian package) - addressed in versions 1:9.11.5.P4+dfsg-5.1+deb10u7, 1:9.16.27-1~deb11u1
Junos OS - addressed in versions 19.4R2-S8, 19.4R3-S9, 20.2R3-S5, 20.3R3-S5, 20.4R3-S4, 21.1R3-S3, 21.2R3-S2, 21.3R3-S1, 21.4R2-S1, 21.4R3, 22.1R1-S2, 22.1R3, 22.2R1-S1, 22.2R2, 22.3R1
HP-UX BIND - update to C.9.11.1.6.0
SINEC INS - update to 1.0 SP2
Netcool Operations Insight - update to 1.6.12
Red Hat OpenShift GitOps - update to 1.12.4
python-sss-murmur - update to 1.16.5-10
libsss_sudo - update to 1.16.5-10
python-sss - update to 1.16.5-10
python-libsss_nss_idmap - update to 1.16.5-10
python-libipa_hbac - update to 1.16.5-10
libsss_simpleifp-devel - update to 1.16.5-10
libsss_simpleifp - update to 1.16.5-10
libsss_nss_idmap-devel - update to 1.16.5-10
libsss_nss_idmap - update to 1.16.5-10
libsss_idmap-devel - update to 1.16.5-10
sssd-ipa - update to 1.16.5-10
libsss_idmap - update to 1.16.5-10
libsss_certmap-devel - update to 1.16.5-10
sssd-dbus - update to 1.16.5-10
sssd-common-pac - update to 1.16.5-10
libipa_hbac - update to 1.16.5-10
libipa_hbac-devel - update to 1.16.5-10
libsss_autofs - update to 1.16.5-10
libsss_certmap - update to 1.16.5-10
sssd-polkit-rules - update to 1.16.5-10
sssd-common - update to 1.16.5-10
sssd-client - update to 1.16.5-10
sssd-ad - update to 1.16.5-10
sssd - update to 1.16.5-10
python-sssdconfig - update to 1.16.5-10
sssd-winbind-idmap - update to 1.16.5-10
sssd-tools - update to 1.16.5-10
sssd-proxy - update to 1.16.5-10
sssd-libwbclient-devel - update to 1.16.5-10
sssd-libwbclient - update to 1.16.5-10
sssd-kcm - update to 1.16.5-10
sssd-krb5 - update to 1.16.5-10
sssd-krb5-common - update to 1.16.5-10
sssd-ldap - update to 1.16.5-10
Ansible Automation Platform - update to 2.4
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
IBM Cloud Transformation Advisor - update to 3.4.0
IBM Cloud Pak for Watson AIOps - update to 3.6.1
EMC ECS - update to 3.7.0.2
dhcp (Red Hat package) - addressed in versions 4.3.6-47.el8_6.2, 4.4.2-17.b1.el9
dhcp - update to 4.4.2-8
dhcp-devel - update to 4.4.2-8
dhcp-debuginfo - update to 4.4.2-8
dhcp-debugsource - update to 4.4.2-8
dhcp-help - update to 4.4.2-8
dhcp - addressed in versions 4.4.2-12.b1.fc34, 4.4.3-2.fc35, 4.4.3-2.fc36
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.3
Red Hat OpenShift Container Platform - addressed in versions 4.12.57, 4.13.42, 4.15.13
OpenShift Virtualization - update to 4.14.6
Session Smart Router - update to 6.2.3-r2
IBM Qradar SIEM - addressed in versions 7.4.3 Fix Pack 9, 7.5.0 Update Pack 5
bind (Red Hat package) main - addressed in versions 9.8.2-0.68.rc1.el6_10.17, 9.11.4-26.P2.el7_9.13, 9.11.13-6.el8_2.11, 9.11.36-3.el8_6.7, 9.11.36-5.el8, 9.16.23-1.el9_0.11, 9.16.23-5.el9_1
bind-doc - addressed in versions 9.9.9P1-63.34.1, 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1, 9.16.31-150400.5.6.1
bind - addressed in versions 9.9.9P1-63.34.1, 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1, 9.16.31-150400.5.6.1
bind-chrootenv - addressed in versions 9.9.9P1-63.34.1, 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
bind-debuginfo - addressed in versions 9.9.9P1-63.34.1, 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1, 9.16.31-150400.5.6.1
bind-debugsource - addressed in versions 9.9.9P1-63.34.1, 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1, 9.16.31-150400.5.6.1
bind-libs-32bit - update to 9.9.9P1-63.34.1
bind-libs - update to 9.9.9P1-63.34.1
bind-libs-debuginfo-32bit - update to 9.9.9P1-63.34.1
bind-libs-debuginfo - update to 9.9.9P1-63.34.1
bind-utils - addressed in versions 9.9.9P1-63.34.1, 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1, 9.16.31-150400.5.6.1
bind-utils-debuginfo - addressed in versions 9.9.9P1-63.34.1, 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1, 9.16.31-150400.5.6.1
bind9 (Ubuntu package) - addressed in versions 1:9.10.3.dfsg.P48ubuntu1.19+esm2, 1:9.11.3+dfsg-1ubuntu1.17, 1:9.16.1-0ubuntu2.10, 1:9.16.15-1ubuntu1.2
bind-lite-devel - update to 9.11.4-26.P2
bind - update to 9.11.4-26.P2
bind-chroot - update to 9.11.4-26.P2
bind-devel - update to 9.11.4-26.P2
bind-export-devel - update to 9.11.4-26.P2
bind-export-libs - update to 9.11.4-26.P2
bind-libs - update to 9.11.4-26.P2
bind-libs-lite - update to 9.11.4-26.P2
bind-license - update to 9.11.4-26.P2
bind-pkcs11 - update to 9.11.4-26.P2
bind-pkcs11-devel - update to 9.11.4-26.P2
bind-pkcs11-libs - update to 9.11.4-26.P2
bind-pkcs11-utils - update to 9.11.4-26.P2
bind-sdb - update to 9.11.4-26.P2
bind-sdb-chroot - update to 9.11.4-26.P2
bind-utils - update to 9.11.4-26.P2
libirs161 - update to 9.11.22-3.40.1
libbind9-161 - update to 9.11.22-3.40.1
libbind9-161-debuginfo - update to 9.11.22-3.40.1
libdns1110 - update to 9.11.22-3.40.1
libdns1110-debuginfo - update to 9.11.22-3.40.1
libisccc161-debuginfo - update to 9.11.22-3.40.1
libirs161-debuginfo - update to 9.11.22-3.40.1
libisc1107-32bit - update to 9.11.22-3.40.1
libisc1107 - update to 9.11.22-3.40.1
libisc1107-debuginfo-32bit - update to 9.11.22-3.40.1
libisc1107-debuginfo - update to 9.11.22-3.40.1
libisccc161 - update to 9.11.22-3.40.1
bind-devel - addressed in versions 9.11.22-3.40.1, 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
python-bind - update to 9.11.22-3.40.1
liblwres161-debuginfo - update to 9.11.22-3.40.1
liblwres161 - update to 9.11.22-3.40.1
libisccfg163-debuginfo - update to 9.11.22-3.40.1
libisccfg163 - update to 9.11.22-3.40.1
libirs-devel - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libns1604 - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
python3-bind - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1, 9.16.31-150400.5.6.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libisccc1600 - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libisc1606 - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libirs1601 - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libdns1605 - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.60.1, 9.16.6-150300.22.16.1
bind9.16 (Red Hat package) - update to 9.16.23-0.7.el8_6.9
bind9.16-libs - update to 9.16.23-0.9
bind9.16-utils - update to 9.16.23-0.9
bind9.16-doc - update to 9.16.23-0.9
bind9.16-license - update to 9.16.23-0.9
python3-bind9.16 - update to 9.16.23-0.9
bind9.16-chroot - update to 9.16.23-0.9
bind9.16 - update to 9.16.23-0.9
bind9.16-dnssec-utils - update to 9.16.23-0.9
bind9.16 (Red Hat package) - update to 9.16.23-0.9.el8.1
bind - update to 9.16.23-8
python3-bind - update to 9.16.23-8
bind-debuginfo - update to 9.16.23-8
bind-pkcs11 - update to 9.16.23-8
bind-export-devel - update to 9.16.23-8
bind-pkcs11-devel - update to 9.16.23-8
bind-devel - update to 9.16.23-8
bind-export-libs - update to 9.16.23-8
bind-chroot - update to 9.16.23-8
bind-libs-lite - update to 9.16.23-8
bind-libs - update to 9.16.23-8
bind-utils - update to 9.16.23-8
bind-debugsource - update to 9.16.23-8
bind - update to 9.16.27-1
bind - addressed in versions 9.16.27-1.fc34, 9.16.27-1.fc35, 9.16.27-1.fc36
net-dns/bind-tools - update to 9.16.33
net-dns/bind - update to 9.16.33
bind-dyndb-ldap - addressed in versions 11.9-9.fc34, 11.9-11.fc35, 11.9-14.fc36
Robotic Process Automation for Cloud Pak - update to 21.0.7
Juniper Junos Space - update to 23.1R1
External References
Related Security Bulletins
- Multiple vulnerabilities in ISC BIND
- Slackware Linux update for bind
- Ubuntu update for bind9
- Ubuntu update for bind9
- Debian update for bind9
- Slackware Linux update for bind
- Multiple vulnerabilities in IBM i
- IBM AIX update for ISC BIND
- IBM VIOS update for ISC BIND
- SUSE update for bind
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in Dell Elastic Cloud Storage (ECS)
- Junos OS update for Bind
- Gentoo update for ISC BIND
- Red Hat Enterprise Linux 8 update for bind9.16
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 9 update for dhcp
- Red Hat Enterprise Linux 9 update for bind
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Robotic Process Automation for Cloud Pak
- Red Hat Enterprise Linux 7 update for bind
- CentOS 7 update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- SUSE update for bind
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Juniper Junos Space
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- openEuler 22.03 LTS update for bind
- openEuler update for dhcp
- Multiple vulnerabilities in Netcool Operations Insight
- Red Hat Enterprise Linux 8.6 Extended Update Support update for bind and dhcp
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.13
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.12
- Multiple vulnerabilities in OpenShift Virtualization 4.14
- Multiple vulnerabilities in OpenShift Service Mesh 2.5
- Multiple vulnerabilities in OpenShift Service Mesh 2.4
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in Red Hat OpenShift GitOps 1.12
- Amazon Linux AMI update for bind
- Fedora 36 update for bind, bind-dyndb-ldap
- Fedora 35 update for bind, bind-dyndb-ldap
- Fedora 34 update for bind, bind-dyndb-ldap
- Fedora 36 update for dhcp
- Fedora 35 update for dhcp
- Fedora 34 update for dhcp
- Multiple vulnerabilities in HPE HP-UX BIND
- Anolis OS update for bind9.16
- Anolis OS update for bind
- Anolis OS update for sssd
- Red Hat Enterprise Linux 8 update for bind
- Red Hat Enterprise Linux 9 update for bind
- Red Hat Enterprise Linux 8 update for bind9.16
- Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION update for bind