ISC patches fourteen BIND vulnerabilities, including DoH crash bug
The Internet Systems Consortium (ISC) rolled out two new versions of its widely used BIND DNS server—9.20.29 and 9.21.26—addressing fourteen security flaws that were publicly disclosed on September 16.
Among the corrected issues is a particularly concerning defect that could trigger an unauthenticated crash on any BIND instance that provides DNS-over-HTTPS (DoH) services. Because DoH is increasingly employed to encrypt DNS queries and bypass traditional network filtering, a failure in that pathway could disrupt both consumer privacy tools and enterprise DNS infrastructure.
ISC’s advisory notes that the DoH‑related flaw does not require specially crafted input; merely receiving a normal DoH request can cause the server to terminate unexpectedly. The vulnerability is classified as a denial‑of‑service condition rather than a remote code execution risk, but the potential for widespread service interruption has prompted rapid adoption of the patches.
BIND remains the most prevalent open‑source authoritative and recursive DNS server on the internet, powering everything from small business networks to large‑scale ISP resolvers. Security updates to such critical infrastructure are closely watched because DNS failures can cascade, affecting web access, email delivery, and other online services that depend on name resolution.
In the weeks following the September disclosure, security researchers and system administrators began scanning for vulnerable installations. Early reports indicated that a handful of public resolvers were still running older, unpatched versions, underscoring the challenge of keeping a fragmented ecosystem up to date.
ISC recommends that operators upgrade to the newly released versions as soon as possible and verify that DoH endpoints are correctly configured after the update. The organization also advises administrators to review their logging and monitoring setups to detect any abnormal termination events that could signal an attempted exploitation.
The patches arrive amid a broader industry focus on DNS security, including the ongoing deployment of DNSSEC, DNS‑over‑TLS, and other encryption mechanisms. While the DoH crash bug does not compromise data confidentiality, it highlights the trade‑offs between adding new features and maintaining robustness in core network services.
Looking ahead, ISC has indicated that it will continue to audit BIND’s codebase for similar classes of bugs and will provide regular security advisories. Users who rely on BIND for critical DNS functions are urged to stay current with future releases and to follow best practices for hardening their DNS infrastructure.
Comments (0)
Be the first to comment.
Join the discussion