CVE-2017-3140: ISC BIND

Medium severity, CVSS 5.9. EPSS: 12.2% chance of exploitation in the next 30 days.

If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.

Affected products

  • ISC BIND: from 9.11.0, up to and including 9.11.1; version 9.9.10 only; version 9.10.5 only
  • Netapp Data Ontap Edge: affected versions not specified
  • Netapp Element Software: affected versions not specified
  • Netapp Oncommand Balance: affected versions not specified

Published 2019-01-16. Last modified 2026-06-17.