In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.
CVE-2021-25216
Score 9.8 from GitHub Security Advisory (severity: CRITICAL) published 2022-05-24. NVD baseline CVSS 8.1; sources differ by 1.7.
- High exploitation likelihood — EPSS 82%
A fix is available — apply it.
- CVSS v3
- 8.1
- EG Score
- 9.8(medium)
- EG Risk
- 82(Track*)EG Risk 82/100SSVC: Track*
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity98% × 45%Exploitation82% × 40%Automatability30% × 15%Action: Watch closely — could escalate to Attend. - EPSS PROB
- 82%
- EPSS %ILE
- 100%
- KEV
- Not listed
Published
April 29, 2021
Last Modified
November 21, 2024
Advisory Details (10)
Auto-updated Sep 18, 2026ZDI-21-657 - TrendAI™ Zero Day Initiative™ (ZDI)
https://www.zerodayinitiative.com/advisories/ZDI-21-657/[SECURITY] [DLA 2647-1] bind9 security update
https://lists.debian.org/debian-lts-announce/2021/05/msg00001.htmlCVE-2021-25215: An assertion check can fail while answering queries fo
https://kb.isc.org/v1/docs/cve-2021-25215oss-security - Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)
http://www.openwall.com/lists/oss-security/2021/04/29/4oss-security - Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)
http://www.openwall.com/lists/oss-security/2021/04/29/3oss-security - Re: ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)
http://www.openwall.com/lists/oss-security/2021/04/29/2oss-security - ISC discloses three BIND vulnerabilities (CVE-2021-25214, CVE-2021-25215, and CVE-2021-25216)
http://www.openwall.com/lists/oss-security/2021/04/29/1Patch Availability(2)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| ubuntu | dnsutils (1:9.16.8-1ubuntu3.1) @ hirsute | 2026-05-26 | ubuntu |
| ubuntu | lwresd (1:9.9.5.dfsg-3ubuntu0.19+esm13) @ trusty | 2026-05-26 | ubuntu |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(21 across 21 ecosystems)
Alpine:v3.10(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.11(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.12(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.15(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.16(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.17(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.18(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.19(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.20(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.21(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.22(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.23(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Alpine:v3.24(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind | — | 9.16.15-r0 | — |
Debian:10(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind9 | 1:9.11.5.P4+dfsg-5.1, 1:9.11.5.P4+dfsg-5.1+deb10u1, 1:9.11.5.P4+dfsg-5.1+deb10u2, 1:9.11.5.P4+dfsg-5.1+deb10u3, 1:9.11.5.P4+dfsg-5.1+deb10u4 | 1:9.11.5.P4+dfsg-5.1+deb10u5 | — |
Debian:11(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind9 | — | 1:9.16.15-1 | — |
Debian:12(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind9 | — | 1:9.16.15-1 | — |
Debian:13(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind9 | — | 1:9.16.15-1 | — |
Debian:14(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind9 | — | 1:9.16.15-1 | — |
Debian:9(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| bind9 | 1:9.10.3.dfsg.P4-12.3 ... 1:9.10.3.dfsg.P4-12.3+deb9u8 (9 versions) | 1:9.10.3.dfsg.P4-12.3+deb9u9 | — |
Weakness Classification(3)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
All Vendor Advisories
(3)
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
Data Freshness Timeline
(refreshed 5× in last 7d / 19× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-19 15:37 UTCEPSS rescore
- 2026-09-18 19:23 UTCEPSS rescore
- 2026-09-16 14:05 UTCEPSS rescore
- 2026-09-15 03:06 UTCEPSS rescore
- 2026-09-15 03:06 UTCEPSS rescore
- 2026-09-12 14:57 UTCEPSS rescore
- 2026-09-08 21:56 UTCEPSS rescore
- 2026-09-06 18:13 UTCOSV refresh
- 2026-09-06 13:44 UTCEPSS rescore
- 2026-09-05 15:25 UTCEPSS rescore
- 2026-09-04 05:03 UTCEPSS rescore
- 2026-09-04 05:03 UTCEPSS rescore
- 2026-08-30 19:14 UTCEPSS rescore
- 2026-08-28 21:37 UTCEPSS rescore
- 2026-08-26 14:42 UTCEPSS rescore
- 2026-08-25 13:45 UTCEPSS rescore
- 2026-08-24 14:12 UTCEPSS rescore
- 2026-08-21 23:46 UTCEPSS rescore
- 2026-08-20 22:52 UTCEPSS rescore
- 2026-08-20 04:34 UTCOSV refresh
- 2026-08-18 13:45 UTCEPSS rescore
- 2026-08-16 02:11 UTCEPSS rescore
- 2026-08-16 02:11 UTCEPSS rescore
- 2026-08-13 21:57 UTCEPSS rescore
- 2026-08-05 19:14 UTCEPSS rescore
Show 74 moreShow fewer
- 2026-08-04 23:40 UTCOSV refresh
- 2026-07-30 01:28 UTCEPSS rescore
- 2026-07-30 01:27 UTCEPSS rescore
- 2026-07-28 15:33 UTCEPSS rescore
- 2026-07-26 14:52 UTCEPSS rescore
- 2026-07-26 14:52 UTCEPSS rescore
- 2026-07-24 14:15 UTCEPSS rescore
- 2026-07-23 01:58 UTCEG score recompute
- 2026-07-22 22:45 UTCEG score recompute
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-22 14:06 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-20 17:05 UTCEPSS rescore
- 2026-07-19 14:28 UTCEPSS rescore
- 2026-07-18 21:29 UTCOSV refresh
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 16:55 UTCEPSS rescore
- 2026-07-15 01:58 UTCEPSS rescore
- 2026-07-11 08:25 UTCEPSS rescore
- 2026-07-11 08:25 UTCEPSS rescore
- 2026-07-08 15:12 UTCEPSS rescore
- 2026-07-06 02:21 UTCEPSS rescore
- 2026-07-06 02:21 UTCEPSS rescore
- 2026-07-05 02:28 UTCEPSS rescore
- 2026-07-04 06:29 UTCEPSS rescore
- 2026-07-04 06:29 UTCEPSS rescore
- 2026-07-01 15:03 UTCEPSS rescore
- 2026-07-01 04:18 UTCOSV refresh
- 2026-06-29 14:04 UTCEPSS rescore
- 2026-06-28 14:05 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-27 03:06 UTCEPSS rescore
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-18 17:51 UTCEPSS rescore
- 2026-06-18 17:51 UTCEPSS rescore
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-14 23:15 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-13 22:58 UTCEPSS rescore
- 2026-06-13 07:13 UTCOSV refresh
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-10 22:16 UTCEPSS rescore
- 2026-06-10 13:20 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-02 20:11 UTCEPSS rescore
- 2026-06-02 20:11 UTCEPSS rescore
- 2026-06-02 20:11 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-31 22:29 UTCEPSS rescore
- 2026-05-29 13:42 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-26 17:17 UTCEG score recompute
- 2026-05-26 17:17 UTCVendor advisory
- 2026-05-26 17:17 UTCGHSA enrichment
- 2026-05-26 13:42 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
- 2026-05-26 07:17 UTCEPSS rescore
Related CVEs(same vendor + same CWE)
Same vendor
10 shownubuntu
- CVE-2004-0989EG 10.0EPSS p98HIGH
- CVE-2004-0990EG 10.0EPSS p98HIGH
- CVE-2004-1010EG 10.0EPSS p95HIGH
- CVE-2004-0941EG 10.0EPSS p96HIGH
- CVE-2004-0981EG 10.0EPSS p93HIGH
- CVE-2004-0882EG 10.0EPSS p96HIGH
- CVE-2004-0888EG 10.0EPSS p95HIGH
- CVE-2004-1012EG 10.0EPSS p93HIGH
- CVE-2004-1013EG 10.0EPSS p93HIGH
- CVE-2004-1018EG 10.0EPSS p97HIGH
Same CWE
10 shownCWE-190 · CWE-125
- CVE-2010-3254EG 10.0HIGH
- CVE-2009-2523EG 10.0EPSS p98HIGH
- CVE-2008-2663EG 10.0EPSS p91HIGH
- CVE-2009-0947EG 9.8CRITICAL
- CVE-2005-1141EG 9.8CRITICAL
- CVE-2005-0102EG 9.8CRITICAL
- CVE-2002-0391EG 9.8EPSS p99CRITICAL
- CVE-2002-0639EG 9.8EPSS p97CRITICAL
- CVE-1999-0006EG 9.8EPSS p96CRITICAL
- CVE-2009-2949EG 9.3EPSS p96HIGH
Frequently asked(5)
What is CVE-2021-25216?
When was CVE-2021-25216 disclosed?
Is CVE-2021-25216 actively exploited?
What is the CVSS score of CVE-2021-25216?
How do I remediate CVE-2021-25216?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2021-25216
Is Your Infrastructure Affected by CVE-2021-25216?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.