A critical vulnerability in the BIND 9 DNS server allows an unauthenticated attacker to crash the service with a single crafted request, turning a privacy-enhancing feature into a point of failure. The Internet Systems Consortium (ISC) has released emergency patches to address the flaw, which specifically targets the DNS-over-HTTPS (DoH) implementation.

ISC disclosed 14 security vulnerabilities on 16 September, providing fixes in BIND versions 9.20.29 and 9.21.26. The most severe issue, affecting any BIND server answering DoH queries, enables an attacker to send a malformed DNS request with an invalid SIG record. This instantly terminates the named process, taking the DNS server offline without requiring any authentication or credentials.

The exploit demands minimal effort—a single request suffices—posing a high risk to the vast portion of the internet that relies on BIND for name resolution. Because BIND underpins core services like web browsing, email, and authentication, widespread attacks could trigger cascading disruptions across enterprises, ISPs, and cloud platforms.

This incident highlights a security paradox: protocols designed to strengthen privacy, such as DoH, can introduce new attack surfaces if implementation flaws exist. The patch release, containing 14 total fixes, underscores the intensive maintenance required to secure long-standing critical internet software.

Administrators must prioritize immediate upgrades to the patched versions. Where upgrades are not immediately possible, disabling the DoH listener on public-facing interfaces can provide temporary mitigation. With the vulnerability being remotely exploitable and unauthenticated, delayed patching leaves systems exposed to denial-of-service attacks.

Ultimately, this disclosure reinforces that layered security measures demand careful implementation and prompt patching to protect foundational network infrastructure.


BIND 9 DNS 伺服器中存在一個嚴重漏洞,允許未經認證的攻擊者透過單一惡意製作的請求癱瘓服務,將一項增強隱私的功能轉變為系統失效點。互聯網系統協會(ISC)已發布緊急補丁以解決此漏洞,該漏洞專門針對 DNS-over-HTTPS(DoH)的實作方式。

ISC 於 9 月 16 日披露了 14 項安全漏洞,並在 BIND 版本 9.20.29 和 9.21.26 中提供修復。最嚴重的問題影響所有回應 DoH 查詢的 BIND 伺服器,攻擊者可傳送包含無效 SIG 記錄的格式錯誤 DNS 請求。這將立即終止 named 程序,使 DNS 伺服器離線,且無需任何認證或憑證。

該攻擊所需努力極小——僅需一個請求——對依賴 BIND 進行名稱解析的廣大互聯網部分構成高風險。由於 BIND 支援網頁瀏覽、電郵及認證等核心服務,大規模攻擊可能引發企業、互聯網服務供應商及雲端平台的連鎖中斷。

此事件突顯了一個安全悖論:旨在加強隱私的協議(如 DoH)若存在實作缺陷,可能引入新的攻擊面。包含 14 項修復的補丁發布,強調了保障長期存在的關鍵互聯網軟件安全所需的密集維護工作。

管理員必須優先立即升級至已修補版本。若無法立即升級,在面向公共的介面上停用 DoH 監聽器可提供暫時緩解措施。由於該漏洞可遠端利用且無需認證,延遲補丁將使系統暴露於拒絕服務攻擊風險中。

此次披露最終重申,分層安全措施需要謹慎的實作與及時的補丁修復,以保護基礎網絡基礎設施。

新聞來源 / Original News Source