CVE-2024-4076: ISC BIND
High severity, CVSS 7.5. EPSS: 2.1% chance of exploitation in the next 30 days.
Client queries that trigger serving stale data and that also require lookups in local authoritative zone data may result in an assertion failure. This issue affects BIND 9 versions 9.16.13 through 9.16.50, 9.18.0 through 9.18.27, 9.19.0 through 9.19.24, 9.11.33-S1 through 9.11.37-S1, 9.16.13-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.27-S1.
Affected products
- ISC BIND: from 9.16.13, up to and including 9.16.50; from 9.18.0, up to and including 9.18.27; from 9.19.0, up to and including 9.19.24; from 9.11.33-s1, up to and including 9.11.37-s1; from 9.16.13-s1, up to and including 9.16.50-s1; from 9.18.11-s1, up to and including 9.18.27-s1
- ISC BIND 9: from 9.16.13, up to and including 9.16.50; from 9.18.0, up to and including 9.18.27; from 9.19.0, up to and including 9.19.24; from 9.11.33-S1, up to and including 9.11.37-S1; from 9.16.13-S1, up to and including 9.16.50-S1; from 9.18.11-S1, up to and including 9.18.27-S1
Published 2024-07-23. Last modified 2026-06-17.