CVE-2021-25219 Details
Description
In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance. The way the lame cache is currently designed makes it possible for its internal data structures to grow almost infinitely, which may cause significant delays in client query processing.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| isc bind | >= 9.3.0, < 9.11.36 >= 9.12.0, < 9.16.22 >= 9.17.0, < 9.17.19 9.9.3 s1 9.9.12 s1 9.9.13 s1 9.10.5 s1 9.10.7 s1 9.11.3 s1 9.11.5 s3 9.11.5 s5 9.11.5 s6 9.11.6 s1 9.11.7 s1 9.11.8 s1 9.11.12 s1 9.11.21 s1 9.11.27 s1 9.11.29 s1 9.11.35 s1 9.16.8 s1 9.16.11 s1 9.16.13 s1 9.16.21 s1 |
CPE
Remediation
| |
| debian debian linux | 9.0 10.0 11.0 |
CPE
Remediation
| |
| fedoraproject fedora | 33 34 35 |
CPE
Remediation
| |
| netapp h300s firmware | All versions |
CPE
Remediation
| |
| netapp h300s | All versions |
CPE
Remediation
| |
| netapp h500s firmware | All versions |
CPE
Remediation
| |
| netapp h500s | All versions |
CPE
Remediation
| |
| netapp h700s firmware | All versions |
CPE
Remediation
| |
| netapp h700s | All versions |
CPE
Remediation
| |
| netapp h300e firmware | All versions |
CPE
Remediation
| |
| netapp h300e | All versions |
CPE
Remediation
| |
| netapp h500e firmware | All versions |
CPE
Remediation
| |
| netapp h500e | All versions |
CPE
Remediation
| |
| netapp h700e firmware | All versions |
CPE
Remediation
| |
| netapp h700e | All versions |
CPE
Remediation
| |
| netapp h410s firmware | All versions |
CPE
Remediation
| |
| netapp h410s | All versions |
CPE
Remediation
| |
| netapp h410c firmware | All versions |
CPE
Remediation
| |
| netapp h410c | All versions |
CPE
Remediation
| |
| netapp cloud backup | All versions |
CPE
Remediation
| |
| siemens sinec infrastructure network services | < 1.0.1.1 |
CPE
Remediation
| |
| oracle http server | 12.2.1.3.0 12.2.1.4.0 |
CPE
Remediation
| |
| oracle zfs storage appliance kit | 8.8 |
CPE
Remediation
| |
Change History
18 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Dec 8, 2022 | Modified Analysis | [email protected] |
| Oct 31, 2022 | CVE Modified | [email protected] |
| Apr 25, 2022 | Modified Analysis | [email protected] |
| Apr 20, 2022 | CVE Modified | [email protected] |
| Mar 10, 2022 | CVE Modified | [email protected] |
| Nov 28, 2021 | Modified Analysis | [email protected] |
| Nov 18, 2021 | CVE Modified | [email protected] |
| Nov 11, 2021 | CVE Modified | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Nov 10, 2021 | CVE Modified | [email protected] |
| Nov 4, 2021 | CVE Modified | [email protected] |
| Nov 3, 2021 | Initial Analysis | [email protected] |
| Nov 2, 2021 | CVE Modified | [email protected] |
| Oct 29, 2021 | CVE Modified | [email protected] |