Vulnerability record · CVE-2016-2775 · published 19 July 2016
CVE-2016-2775: ISC BIND lwresd long request denial of service
Hp · Hp Ux
ISC BIND 9.x, 9.10.x and 9.11.x crash when lwresd or the named lwres option is enabled and a remote attacker sends a long request using the lightweight resolver protocol. The flaw is improper input validation (CWE-20) in the lwres request handling path, and it matters because it can take down a DNS resolver daemon that has this optional feature turned on.
Description
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
medium priorityCVSS rates this medium (5.9) with availability-only impact, but the high EPSS score and the fact that exposure depends on the optional lwres feature keep it worth prompt patching.
What it is
ISC BIND 9.x, 9.10.x and 9.11.x crash when lwresd or the named lwres option is enabled and a remote attacker sends a long request using the lightweight resolver protocol. The flaw is improper input validation (CWE-20) in the lwres request handling path, and it matters because it can take down a DNS resolver daemon that has this optional feature turned on.
Impact
An unauthenticated remote attacker can crash the BIND daemon, causing a denial of service for DNS resolution on the affected host. There is no confidentiality or integrity impact; only availability is affected.
Attack surface
Reachable over the network via the lightweight resolver protocol when lwresd or the named lwres option is enabled; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). Systems running BIND without the lwres feature are not exposed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS gives a 30-day probability of 0.63346 (99.171 percentile), and references are advisories and patch notes rather than exploit code, so no confirmed in-the-wild exploitation is recorded here.
What to do
- Upgrade BIND to 9.9.9-P2, 9.10.4-P2, 9.11.0b2 or later as directed by the ISC advisory AA-01393 and vendor errata.
- If the lightweight resolver is not needed, disable lwresd and remove the named lwres option to eliminate exposure.
- Restrict network access to the lwres service to trusted clients only, since the protocol is not required for normal DNS service.
- Apply the Red Hat, Fedora, HP-UX and NetApp vendor updates for the affected BIND packages.
- Monitor for repeated daemon restarts or crashes on hosts running BIND with lwres enabled.
Detection
- Watch BIND/named or lwresd logs for unexpected crashes, core dumps or restart loops correlated with lwres traffic.
- Alert on unusually long or malformed lightweight resolver protocol requests reaching the lwres port.
- Baseline which hosts have lwresd or the named lwres option enabled and monitor those specifically for availability loss.
- Use host or service monitoring to detect sudden loss of DNS resolution from a BIND server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2016-2775 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2016-2775), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.