Zero-day suspected in BIND 9 DNS server crashes

BIND 9 DNS servers across the web have crashed, with a zero-day vulnerability believed to be the cause.

Threat

A zero-day vulnerability is the suspected cause of BIND 9 DNS server crashes occurring across the web.

BIND 9 is the most widely used DNS server on the internet, meaning the flaw could have a massive impact.

"Organisations across the internet reported crashes interrupting service on BIND 9 nameservers performing recursive queries... An as-yet unidentified network event caused BIND 9 resolvers to cache an invalid record, subsequent queries for which could crash the resolvers with an assertion failure," the Internet Systems Consortium (ISC) said in an advisory.

"ISC is working on determining the ultimate cause by which a record with this particular inconsistency is cached."

ISC, which manages the BIND software, has issued patches to prevent servers from crashing.

"At this time we are making available a patch which makes named recover gracefully from the inconsistency, preventing the abnormal exit," it added.

Security intelligence firm Rapid7 said the first attack was discovered at The National Weather Service, with the following 89 discoveries of the attack on US universities.

"Bind 9 is the most widely used DNS server on the internet today Gone unchecked, this attack could potentially affect nearly the entire internet," said Matt Barrett, senior solutions architect at Rapid7.

"A temporary patch has already been released, but we encourage everyone to submit packet-capture from their own systems to ISC so they can further investigate. As with any attack, the more information gathered, the better we'll be."

Featured Resources

Seven steps to connect and empower your frontline workers

How business leaders can improve communication with a secure platform

Free download

Create what’s next

The future of collaboration and productivity

Free Download

Leveraging the cloud without relinquishing control

Your data. Their cloud.

Free download

Re-architecting for nonstop innovation

Unlocking productivity, scalability, and lower costs for cloud natives

Free Download

Recommended

Hackers could use new Wslink malware in highly targeted cyber attacks
malware

Hackers could use new Wslink malware in highly targeted cyber attacks

1 Nov 2021
FBI raids Chinese POS business following cyber attack claims
malware

FBI raids Chinese POS business following cyber attack claims

27 Oct 2021
Malware developers create malformed code signatures to avoid detection
malware

Malware developers create malformed code signatures to avoid detection

24 Sep 2021
New malware uses search engine ads to target pirate gamers
malware

New malware uses search engine ads to target pirate gamers

21 Jul 2021

Most Popular

How to speed up Microsoft's Windows 11
Microsoft Windows

How to speed up Microsoft's Windows 11

9 Nov 2021
Nike to take customers into the metaverse with 'NIKELAND'
virtualisation

Nike to take customers into the metaverse with 'NIKELAND'

19 Nov 2021
Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

12 Nov 2021