Vulnerability record · CVE-2022-3736 · published 26 January 2023
CVE-2022-3736: BIND 9 resolver crash via RRSIG query with stale-answer options enabled
Isc · Bind
BIND 9 can crash when stale cache and stale answers are enabled, the stale-answer-client-timeout option is set to a positive integer, and the resolver receives an RRSIG query. The flaw is an improper input validation issue that lets a remote query terminate the resolver process, disrupting DNS resolution for downstream clients.
Description
BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityRemote unauthenticated crash of a core DNS resolver with a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
BIND 9 can crash when stale cache and stale answers are enabled, the stale-answer-client-timeout option is set to a positive integer, and the resolver receives an RRSIG query. The flaw is an improper input validation issue that lets a remote query terminate the resolver process, disrupting DNS resolution for downstream clients.
Impact
An unauthenticated remote attacker can cause a denial of service by crashing the BIND resolver, interrupting name resolution for all clients relying on it. No confidentiality or integrity impact is described; only availability is affected.
Attack surface
Reachable over the network via DNS queries (AV:N, PR:N, UI:N), specifically an RRSIG query sent to a resolver configured with stale cache, stale answers, and a positive stale-answer-client-timeout. No authentication or user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.487 (98.8th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade BIND to a version outside the affected ranges (9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and the 9.16.12-S1 through 9.16.36-S1 branches) per the ISC advisory.
- If patching cannot be done immediately, disable stale cache/stale answers or set stale-answer-client-timeout to 0 to remove the triggering condition.
- Restrict or rate-limit DNS query sources where feasible to reduce exposure to untrusted RRSIG queries.
- Monitor resolver processes for unexpected restarts and correlate with inbound RRSIG query patterns.
- Track the ISC vendor advisory for updated fixed versions and guidance.
Detection
- Alert on BIND/named process crashes or unexpected restarts and correlate with recent RRSIG query activity.
- Log and review inbound RRSIG (type 46) queries to resolvers, especially from untrusted sources.
- Verify resolver configuration for stale-answer-client-timeout and stale cache settings, and flag hosts where the vulnerable combination is enabled.
- Monitor DNS resolution failures or timeouts from clients served by affected resolvers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://kb.isc.org/docs/cve-2022-3736 | Vendor Advisory |
| https://kb.isc.org/docs/cve-2022-3736 | Vendor Advisory |
Track CVE-2022-3736 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-3736), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.