← Vulnerability feed

Vulnerability record · CVE-2016-2775 · published 19 July 2016

CVE-2016-2775: ISC BIND lwresd long request denial of service

Hp · Hp Ux

ISC BIND 9.x, 9.10.x and 9.11.x crash when lwresd or the named lwres option is enabled and a remote attacker sends a long request using the lightweight resolver protocol. The flaw is improper input validation (CWE-20) in the lwres request handling path, and it matters because it can take down a DNS resolver daemon that has this optional feature turned on.

5.9 CVSS 3.1 Medium EPSS 63% · top 0.8% CWE-20 · Improper input validation
5.9CVSS 3.1 base score, v2 4.3
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
9Affected product versions listed by NVD
32References
17 Jun 2026Last modified by NVD

Description

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

medium priorityCVSS rates this medium (5.9) with availability-only impact, but the high EPSS score and the fact that exposure depends on the optional lwres feature keep it worth prompt patching.

What it is

ISC BIND 9.x, 9.10.x and 9.11.x crash when lwresd or the named lwres option is enabled and a remote attacker sends a long request using the lightweight resolver protocol. The flaw is improper input validation (CWE-20) in the lwres request handling path, and it matters because it can take down a DNS resolver daemon that has this optional feature turned on.

Impact

An unauthenticated remote attacker can crash the BIND daemon, causing a denial of service for DNS resolution on the affected host. There is no confidentiality or integrity impact; only availability is affected.

Attack surface

Reachable over the network via the lightweight resolver protocol when lwresd or the named lwres option is enabled; no authentication or user interaction is required per the CVSS vector (AV:N/PR:N/UI:N). Systems running BIND without the lwres feature are not exposed.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS gives a 30-day probability of 0.63346 (99.171 percentile), and references are advisories and patch notes rather than exploit code, so no confirmed in-the-wild exploitation is recorded here.

What to do

  • Upgrade BIND to 9.9.9-P2, 9.10.4-P2, 9.11.0b2 or later as directed by the ISC advisory AA-01393 and vendor errata.
  • If the lightweight resolver is not needed, disable lwresd and remove the named lwres option to eliminate exposure.
  • Restrict network access to the lwres service to trusted clients only, since the protocol is not required for normal DNS service.
  • Apply the Red Hat, Fedora, HP-UX and NetApp vendor updates for the affected BIND packages.
  • Monitor for repeated daemon restarts or crashes on hosts running BIND with lwres enabled.

Detection

  • Watch BIND/named or lwresd logs for unexpected crashes, core dumps or restart loops correlated with lwres traffic.
  • Alert on unusually long or malformed lightweight resolver protocol requests reaching the lwres port.
  • Baseline which hosts have lwresd or the named lwres option enabled and monitor those specifically for availability loss.
  • Use host or service monitoring to detect sudden loss of DNS resolution from a BIND server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/92037 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036360 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHBA-2017:0651 Third Party Advisory
https://access.redhat.com/errata/RHBA-2017:1767 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2533 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107 PatchVendor Advisory
https://kb.isc.org/article/AA-01393/74/CVE-2016-2775 PatchVendor Advisory
https://kb.isc.org/article/AA-01435 Broken Link
https://kb.isc.org/article/AA-01436 Broken Link
https://kb.isc.org/article/AA-01438 Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7T2WJP5ELO4ZRSBXSETIZ3G
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZUCSMEOZIZ2R2SKA4FPLTO
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ5STNEUHBNEPUHJT7CYEVS
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT754KDUJTKOASJODJX7FKH
https://security.gentoo.org/glsa/201610-07 Third Party Advisory
https://security.netapp.com/advisory/ntap-20160722-0002/ Third Party Advisory
http://www.securityfocus.com/bid/92037 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036360 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHBA-2017:0651 Third Party Advisory
https://access.redhat.com/errata/RHBA-2017:1767 Third Party Advisory
https://access.redhat.com/errata/RHSA-2017:2533 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05321107 PatchVendor Advisory
https://kb.isc.org/article/AA-01393/74/CVE-2016-2775 PatchVendor Advisory
https://kb.isc.org/article/AA-01435 Broken Link
https://kb.isc.org/article/AA-01436 Broken Link
https://kb.isc.org/article/AA-01438 Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7T2WJP5ELO4ZRSBXSETIZ3G
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MZUCSMEOZIZ2R2SKA4FPLTO
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NJ5STNEUHBNEPUHJT7CYEVS
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TT754KDUJTKOASJODJX7FKH
https://security.gentoo.org/glsa/201610-07 Third Party Advisory
https://security.netapp.com/advisory/ntap-20160722-0002/ Third Party Advisory

Track CVE-2016-2775 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2016-2775), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.