ISC Releases Security Advisories for BIND
Security updates for the Berkeley Internet Name Domain system
Summary
Security updates for the Berkeley Internet Name Domain system
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
The Internet Systems Consortium (ISC) has released security updates that address denial-of-service, cache poisoning, and other vulnerabilities in versions of ISC Berkeley Internet Name Domain (BIND). A remote attacker could exploit these vulnerabilities to take control of a system.
Remediation advice
Affected organisations are encouraged to review the following ISC security advisories and apply the necessary updates or workarounds.
Remediation steps
| Type | Step |
|---|---|
| Patch |
CVE-2021-25220: DNS forwarders - cache poisoning vulnerability https://kb.isc.org/docs/cve-2021-25220 |
| Patch |
CVE-2022-0396: DoS from specifically crafted TCP packets https://kb.isc.org/docs/cve-2022-0396 |
| Patch |
CVE-2022-0635: DNAME insist with synth-from-dnssec enabled https://kb.isc.org/docs/cve-2022-0635 |
| Patch |
CVE-2022-0667: Assertion failure on delayed DS lookup https://kb.isc.org/docs/cve-2022-0667 |
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 18 March 2022 3:55 pm