← Vulnerability feed

Vulnerability record · CVE-2014-8500 · published 11 December 2014

CVE-2014-8500: ISC BIND delegation chaining flaw allows remote denial of service

Isc · Bind

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, so a large or effectively infinite series of referrals exhausts memory and crashes named. Because BIND is widely deployed as recursive and authoritative DNS, an unauthenticated remote crash of the resolver disrupts name resolution for everything behind it.

7.8 CVSS 2.0 High EPSS 58% · top 0.9% CWE-399 · CWE-399
7.8CVSS 2.0 base score
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
54References
17 Jun 2026Last modified by NVD

Description

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory consumption and named crash) via a large or infinite number of referrals.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityUnauthenticated remote crash of a core DNS service with a high EPSS score, though no confirmed in-the-wild exploitation is recorded.

What it is

ISC BIND 9.0.x through 9.8.x, 9.9.0 through 9.9.6, and 9.10.0 through 9.10.1 does not limit delegation chaining, so a large or effectively infinite series of referrals exhausts memory and crashes named. Because BIND is widely deployed as recursive and authoritative DNS, an unauthenticated remote crash of the resolver disrupts name resolution for everything behind it.

Impact

An attacker can consume memory on the BIND server until named crashes, causing a denial of service for DNS resolution. There is no confidentiality or integrity impact; the CVSS vector is C:N/I:N/A:C.

Attack surface

Reachable over the network via DNS queries that trigger referral chains; the CVSS vector AV:N/AC:L/Au:N means no authentication and no user interaction are required. Any BIND instance that processes such referrals, including recursive resolvers, is exposed.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.57794, 99th percentile), and references include vendor advisories and patches but no public exploit tag, so exploitation is plausible but not confirmed by this record.

What to do

  • Upgrade to a fixed BIND release; ISC advisory AA-01216 and vendor errata (Ubuntu USN-2437-1, Debian DSA-3094, Red Hat RHSA-2016-0078) identify patched versions.
  • If immediate patching is not possible, restrict recursion to trusted clients and apply rate limiting on inbound DNS queries.
  • Monitor named memory usage and configure automatic restart or failover for resolver instances.
  • Track vendor advisories for bundled BIND in appliances and operating systems, since the affected range spans many downstream products.

Detection

  • Alert on named process crashes or unexpected restarts and correlate with spikes in memory usage.
  • Baseline and monitor referral response volume per client; flag clients generating unusually deep or numerous referral chains.
  • Review DNS query logs for repeated queries producing long delegation chains from a single source.
  • Watch system logs for out-of-memory kills or named fatal errors on DNS servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://advisories.mageia.org/MGASA-2014-0524.html
http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html Vendor Advisory
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.asc
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10676
http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00038.html
http://marc.info/?l=bugtraq&m=142180687100892&w=2
http://marc.info/?l=bugtraq&m=144000632319155&w=2
http://rhn.redhat.com/errata/RHSA-2016-0078.html
http://secunia.com/advisories/62064
http://secunia.com/advisories/62122
http://security.gentoo.org/glsa/glsa-201502-03.xml
http://securitytracker.com/id?1031311
http://ubuntu.com/usn/usn-2437-1 PatchVendor Advisory
http://www.debian.org/security/2014/dsa-3094 Vendor Advisory
http://www.kb.cert.org/vuls/id/264212 Third Party AdvisoryUS Government Resource
http://www.mandriva.com/security/advisories?name=MDVSA-2015:165
http://www.oracle.com/technetwork/topics/security/bulletinjan2015-2370101.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/71590
https://kb.isc.org/article/AA-01216/ Vendor Advisory
https://security.netapp.com/advisory/ntap-20190730-0002/
https://support.apple.com/HT205219
http://advisories.mageia.org/MGASA-2014-0524.html
http://cert.ssi.gouv.fr/site/CERTFR-2014-AVI-512/index.html Vendor Advisory
http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2015-002.txt.asc
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10676
http://lists.apple.com/archives/security-announce/2015/Sep/msg00004.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00017.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00009.html
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00013.html
http://lists.opensuse.org/opensuse-updates/2015-07/msg00038.html
http://marc.info/?l=bugtraq&m=142180687100892&w=2
http://marc.info/?l=bugtraq&m=144000632319155&w=2
http://rhn.redhat.com/errata/RHSA-2016-0078.html

Track CVE-2014-8500 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2014-8500), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.