← Vulnerability feed

Vulnerability record · CVE-2021-25216 · published 29 April 2021

CVE-2021-25216: BIND GSS-TSIG SPNEGO Memory Corruption Enables Crash and Possible RCE

Debian · Debian Linux

BIND servers configured with GSS-TSIG (via tkey-gssapi-keytab or tkey-gssapi-credential) use an ISC SPNEGO implementation that mishandles input, causing an out-of-bounds read on 64-bit builds and a buffer overflow on 32-bit builds. Default BIND configurations do not expose the vulnerable code path, but GSS-TSIG is common where BIND integrates with Samba or Active Directory. The flaw is remotely reachable without authentication, making it serious for any deployment that has enabled these options.

9.8 CVSS 3.1 Critical EPSS 82% · top 0.3% CWE-125 · Out-of-bounds read
9.8CVSS 3.1 base score, v2 6.8
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
14Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 9.8 and very high EPSS indicate severe, remotely reachable impact, but exploitation requires non-default GSS-TSIG configuration, lowering real-world exposure.

What it is

BIND servers configured with GSS-TSIG (via tkey-gssapi-keytab or tkey-gssapi-credential) use an ISC SPNEGO implementation that mishandles input, causing an out-of-bounds read on 64-bit builds and a buffer overflow on 32-bit builds. Default BIND configurations do not expose the vulnerable code path, but GSS-TSIG is common where BIND integrates with Samba or Active Directory. The flaw is remotely reachable without authentication, making it serious for any deployment that has enabled these options.

Impact

An unauthenticated remote attacker can crash the named process on both 32-bit and 64-bit builds, causing denial of service. On 32-bit builds the buffer overflow may also allow remote code execution in the context of the BIND service.

Attack surface

Reachable over the network via the GSS-TSIG/SPNEGO handling path, with no authentication or user interaction required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). Exposure requires the server to be explicitly configured with tkey-gssapi-keytab or tkey-gssapi-credential; default configurations are not vulnerable.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.824, 99.6th percentile), indicating strong predicted likelihood of exploitation. References are advisories and patch notices only; none are tagged as exploit code.

What to do

  • Upgrade to a BIND release that removes the ISC SPNEGO implementation (April 2021 9.11 and 9.16 releases) or a later fixed version.
  • If immediate patching is not possible, remove tkey-gssapi-keytab and tkey-gssapi-credential from named.conf to disable GSS-TSIG and close the vulnerable code path.
  • Where GSS-TSIG is required, rely on the MIT or Heimdal Kerberos SPNEGO implementations instead of the ISC one.
  • Restrict network access to DNS services to trusted clients and management networks to reduce exposure of any remaining vulnerable instances.
  • Inventory BIND deployments, especially those integrated with Samba or Active Directory, to confirm which hosts have GSS-TSIG enabled.

Detection

  • Search named.conf and configuration management baselines for tkey-gssapi-keytab or tkey-gssapi-credential to identify exposed servers.
  • Monitor named process crashes and unexpected restarts, correlating with inbound DNS traffic from untrusted sources.
  • Alert on anomalous or malformed GSS-TSIG/SPNEGO negotiation traffic reaching DNS servers.
  • Track BIND version inventory to flag hosts still running affected 9.5.x through 9.17.1 builds.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

14 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2021/04/29/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/4 Mailing ListThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf PatchThird Party Advisory
https://kb.isc.org/v1/docs/cve-2021-25215 Not Applicable
https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html Mailing ListThird Party Advisory
https://security.netapp.com/advisory/ntap-20210521-0006/ Third Party Advisory
https://www.debian.org/security/2021/dsa-4909 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-657/ Third Party AdvisoryVDB Entry
http://www.openwall.com/lists/oss-security/2021/04/29/1 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/2 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/3 Mailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/4 Mailing ListThird Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf PatchThird Party Advisory
https://kb.isc.org/v1/docs/cve-2021-25215 Not Applicable
https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html Mailing ListThird Party Advisory
https://security.netapp.com/advisory/ntap-20210521-0006/ Third Party Advisory
https://www.debian.org/security/2021/dsa-4909 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-657/ Third Party AdvisoryVDB Entry

Track CVE-2021-25216 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-25216), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.