Vulnerability record · CVE-2021-25216 · published 29 April 2021
CVE-2021-25216: BIND GSS-TSIG SPNEGO Memory Corruption Enables Crash and Possible RCE
Debian · Debian Linux
BIND servers configured with GSS-TSIG (via tkey-gssapi-keytab or tkey-gssapi-credential) use an ISC SPNEGO implementation that mishandles input, causing an out-of-bounds read on 64-bit builds and a buffer overflow on 32-bit builds. Default BIND configurations do not expose the vulnerable code path, but GSS-TSIG is common where BIND integrates with Samba or Active Directory. The flaw is remotely reachable without authentication, making it serious for any deployment that has enabled these options.
Description
In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 9.8 and very high EPSS indicate severe, remotely reachable impact, but exploitation requires non-default GSS-TSIG configuration, lowering real-world exposure.
What it is
BIND servers configured with GSS-TSIG (via tkey-gssapi-keytab or tkey-gssapi-credential) use an ISC SPNEGO implementation that mishandles input, causing an out-of-bounds read on 64-bit builds and a buffer overflow on 32-bit builds. Default BIND configurations do not expose the vulnerable code path, but GSS-TSIG is common where BIND integrates with Samba or Active Directory. The flaw is remotely reachable without authentication, making it serious for any deployment that has enabled these options.
Impact
An unauthenticated remote attacker can crash the named process on both 32-bit and 64-bit builds, causing denial of service. On 32-bit builds the buffer overflow may also allow remote code execution in the context of the BIND service.
Attack surface
Reachable over the network via the GSS-TSIG/SPNEGO handling path, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Exposure requires the server to be explicitly configured with tkey-gssapi-keytab or tkey-gssapi-credential; default configurations are not vulnerable.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.824, 99.6th percentile), indicating strong predicted likelihood of exploitation. References are advisories and patch notices only; none are tagged as exploit code.
What to do
- Upgrade to a BIND release that removes the ISC SPNEGO implementation (April 2021 9.11 and 9.16 releases) or a later fixed version.
- If immediate patching is not possible, remove tkey-gssapi-keytab and tkey-gssapi-credential from named.conf to disable GSS-TSIG and close the vulnerable code path.
- Where GSS-TSIG is required, rely on the MIT or Heimdal Kerberos SPNEGO implementations instead of the ISC one.
- Restrict network access to DNS services to trusted clients and management networks to reduce exposure of any remaining vulnerable instances.
- Inventory BIND deployments, especially those integrated with Samba or Active Directory, to confirm which hosts have GSS-TSIG enabled.
Detection
- Search named.conf and configuration management baselines for tkey-gssapi-keytab or tkey-gssapi-credential to identify exposed servers.
- Monitor named process crashes and unexpected restarts, correlating with inbound DNS traffic from untrusted sources.
- Alert on anomalous or malformed GSS-TSIG/SPNEGO negotiation traffic reaching DNS servers.
- Track BIND version inventory to flag hosts still running affected 9.5.x through 9.17.1 builds.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-25216 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-25216), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.