← Vulnerability feed

Vulnerability record · CVE-2022-3736 · published 26 January 2023

CVE-2022-3736: BIND 9 resolver crash via RRSIG query with stale-answer options enabled

Isc · Bind

BIND 9 can crash when stale cache and stale answers are enabled, the stale-answer-client-timeout option is set to a positive integer, and the resolver receives an RRSIG query. The flaw is an improper input validation issue that lets a remote query terminate the resolver process, disrupting DNS resolution for downstream clients.

7.5 CVSS 3.1 High EPSS 49% · top 1.2% CWE-20 · Improper input validation
7.5CVSS 3.1 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

BIND 9 resolver can crash when stale cache and stale answers are enabled, option `stale-answer-client-timeout` is set to a positive integer, and the resolver receives an RRSIG query. This issue affects BIND 9 versions 9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and 9.16.12-S1 through 9.16.36-S1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote unauthenticated crash of a core DNS resolver with a high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is documented.

What it is

BIND 9 can crash when stale cache and stale answers are enabled, the stale-answer-client-timeout option is set to a positive integer, and the resolver receives an RRSIG query. The flaw is an improper input validation issue that lets a remote query terminate the resolver process, disrupting DNS resolution for downstream clients.

Impact

An unauthenticated remote attacker can cause a denial of service by crashing the BIND resolver, interrupting name resolution for all clients relying on it. No confidentiality or integrity impact is described; only availability is affected.

Attack surface

Reachable over the network via DNS queries (AV:N, PR:N, UI:N), specifically an RRSIG query sent to a resolver configured with stale cache, stale answers, and a positive stale-answer-client-timeout. No authentication or user interaction is required.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.487 (98.8th percentile), indicating elevated likelihood of attempted exploitation.

What to do

  • Upgrade BIND to a version outside the affected ranges (9.16.12 through 9.16.36, 9.18.0 through 9.18.10, 9.19.0 through 9.19.8, and the 9.16.12-S1 through 9.16.36-S1 branches) per the ISC advisory.
  • If patching cannot be done immediately, disable stale cache/stale answers or set stale-answer-client-timeout to 0 to remove the triggering condition.
  • Restrict or rate-limit DNS query sources where feasible to reduce exposure to untrusted RRSIG queries.
  • Monitor resolver processes for unexpected restarts and correlate with inbound RRSIG query patterns.
  • Track the ISC vendor advisory for updated fixed versions and guidance.

Detection

  • Alert on BIND/named process crashes or unexpected restarts and correlate with recent RRSIG query activity.
  • Log and review inbound RRSIG (type 46) queries to resolvers, especially from untrusted sources.
  • Verify resolver configuration for stale-answer-client-timeout and stale cache settings, and flag hosts where the vulnerable combination is enabled.
  • Monitor DNS resolution failures or timeouts from clients served by affected resolvers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-3736 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2022-3736), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.