CVE-2021-25216

CVSS v3.1 9.8 (Critical)
98% Progress
CVSS v2.0 6.8 (Medium)
68% Progress
EPSS 44.74 % (97th)
44.74% Progress
Affected Products 23
Advisories 7

In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.

Weaknesses
CWE-125
Out-of-bounds Read
CVE Status
PUBLISHED
CNA
Internet Systems Consortium (ISC)
Published Date
2021-04-29 01:15:08
(3 years ago)
Updated Date
2022-05-03 16:04:40
(2 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

AND
    CPE23 From Up To
OR  
  Debian Linux 9.0 cpe:2.3:o:debian:debian_linux:9.0
OR  
  Running on/with
  Debian Linux 10.0 cpe:2.3:o:debian:debian_linux:10.0

Configuration #2

AND
    CPE23 From Up To
OR  
  Isc Bind from 9.0.0 version and prior 9.11.31 version cpe:2.3:a:isc:bind::*:*:*:- >= 9.0.0 < 9.11.31
OR  
  Running on/with
  Isc Bind from 9.12.0 version and prior 9.16.15 version cpe:2.3:a:isc:bind::*:*:*:- >= 9.12.0 < 9.16.15
OR  
  Running on/with
  Isc Bind from 9.17.0 version and prior 9.17.12 version cpe:2.3:a:isc:bind::*:*:*:- >= 9.17.0 < 9.17.12
OR  
  Running on/with
  Isc Bind 9.9.3 S1 cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.9.12 S1 cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.9.13 S1 cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.10.5 S1 cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.10.7 S1 cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.3 S1 cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.5 S3 cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.5 S5 cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.5 S6 cpe:2.3:a:isc:bind:9.11.5:s6:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.6 S1 cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.7 S1 cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.8 S1 cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.12 S1 cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.21 S1 cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.27 S1 cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.11.29 S1 cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.16.8 S1 cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.16.11 S1 cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview
OR  
  Running on/with
  Isc Bind 9.16.13 S1 cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview

Configuration #3

AND
    CPE23 From Up To
OR  
  Siemens Sinec Infrastructure Network Services prior 1.0.1.1 version cpe:2.3:a:siemens:sinec_infrastructure_network_services < 1.0.1.1

Configuration #4

AND
    CPE23 From Up To
OR  
  Netapp Active Iq Unified Manager for Vsphere cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere
OR  
  Running on/with
  Netapp Cloud Backup cpe:2.3:a:netapp:cloud_backup:-

Configuration #5

AND
    CPE23 From Up To
OR  
  Netapp Aff A250 Firmware cpe:2.3:o:netapp:aff_a250_firmware:-
OR  
  Running on/with
  Netapp Aff A250 cpe:2.3:h:netapp:aff_a250:-

Configuration #6

AND
    CPE23 From Up To
OR  
  Netapp Aff 500f Firmware cpe:2.3:o:netapp:aff_500f_firmware:-
OR  
  Running on/with
  Netapp Aff 500f cpe:2.3:h:netapp:aff_500f:-

Configuration #7

AND
    CPE23 From Up To
OR  
  Netapp H300s Firmware cpe:2.3:o:netapp:h300s_firmware:-
OR  
  Running on/with
  Netapp H300s cpe:2.3:h:netapp:h300s:-

Configuration #8

AND
    CPE23 From Up To
OR  
  Netapp H500s Firmware cpe:2.3:o:netapp:h500s_firmware:-
OR  
  Running on/with
  Netapp H500s cpe:2.3:h:netapp:h500s:-

Configuration #9

AND
    CPE23 From Up To
OR  
  Netapp H700s Firmware cpe:2.3:o:netapp:h700s_firmware:-
OR  
  Running on/with
  Netapp H700s cpe:2.3:h:netapp:h700s:-

Configuration #10

AND
    CPE23 From Up To
OR  
  Netapp H300e Firmware cpe:2.3:o:netapp:h300e_firmware:-
OR  
  Running on/with
  Netapp H300e cpe:2.3:h:netapp:h300e:-

Configuration #11

AND
    CPE23 From Up To
OR  
  Netapp H500e Firmware cpe:2.3:o:netapp:h500e_firmware:-
OR  
  Running on/with
  Netapp H500e cpe:2.3:h:netapp:h500e:-

Configuration #12

AND
    CPE23 From Up To
OR  
  Netapp H700e Firmware cpe:2.3:o:netapp:h700e_firmware:-
OR  
  Running on/with
  Netapp H700e cpe:2.3:h:netapp:h700e:-

Configuration #13

AND
    CPE23 From Up To
OR  
  Netapp H410s Firmware cpe:2.3:o:netapp:h410s_firmware:-
OR  
  Running on/with
  Netapp H410s cpe:2.3:h:netapp:h410s:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...