CVE-2021-25216 | A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack

In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.

Published: 2021-04-29 Last update: 2026-06-17 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-25216 is rated High Risk (72.3/100): CVSS High severity, with high exploitation likelihood (EPSS 83.41%, 100th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +55.66% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-25216

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 27.74% 83.41% +55.66%
2 2026-03-04 61.24% 27.74% -33.49%
3 2026-03-01 61.24%

Full EPSS history (74 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-25216

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
8.1 3.1 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:H)
Even with access, the exploit needs extra luck, timing, or a fussy environment to actually work.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
2.2 5.9 [email protected]
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 6.4 [email protected]

Weakness enumeration for CVE-2021-25216

OS Trackers for CVE-2021-25216

vendor priority summary link
alpine critical CVE-2021-25216: 1 source package rows (bind); 10 state rows across 10 repos (3.10-main, 3.11-main, 3.12-main, 3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 10, open 0. https://security.alpinelinux.org/vuln/CVE-2021-25216
debian not yet assigned CVE-2021-25216 not yet assigned priority: Debian including 1 source packages (bind9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2021-25216
redhat high https://access.redhat.com/security/cve/CVE-2021-25216
suse high https://www.suse.com/security/cve/CVE-2021-25216/
ubuntu medium CVE-2021-25216 medium priority: Ubuntu including 1 source packages (bind9), 15 status rows across 15 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, trusty, upstream, xenial): released 15. https://ubuntu.com/security/CVE-2021-25216

Affected software / configurations for CVE-2021-25216

Vendor Product Version Raw CPE
debian debian_linux 9.0 cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
debian debian_linux 10.0 cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
isc bind >= 9.0.0, < 9.11.31 cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
isc bind >= 9.12.0, < 9.16.15 cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
isc bind >= 9.17.0, < 9.17.12 cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*
isc bind 9.9.3 cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:*
isc bind 9.9.12 cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:*
isc bind 9.9.13 cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview:*:*:*
isc bind 9.10.5 cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:*
isc bind 9.10.7 cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:*
isc bind 9.11.3 cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:*
isc bind 9.11.5 cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*
isc bind 9.11.5 cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview:*:*:*
isc bind 9.11.5 cpe:2.3:a:isc:bind:9.11.5:s6:*:*:supported_preview:*:*:*
isc bind 9.11.6 cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:*
isc bind 9.11.7 cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:*
isc bind 9.11.8 cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:*
isc bind 9.11.12 cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:*
isc bind 9.11.21 cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:*
isc bind 9.11.27 cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview:*:*:*
isc bind 9.11.29 cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview:*:*:*
isc bind 9.16.8 cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:*
isc bind 9.16.11 cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:*
isc bind 9.16.13 cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:*
siemens sinec_infrastructure_network_services < 1.0.1.1 cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
netapp active_iq_unified_manager cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:*
netapp cloud_backup cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
netapp aff_a250_firmware cpe:2.3:o:netapp:aff_a250_firmware:-:*:*:*:*:*:*:*
netapp aff_500f_firmware cpe:2.3:o:netapp:aff_500f_firmware:-:*:*:*:*:*:*:*
netapp h300s_firmware cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
netapp h500s_firmware cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*
netapp h700s_firmware cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*
netapp h300e_firmware cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:*
netapp h500e_firmware cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:*
netapp h700e_firmware cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:*
netapp h410s_firmware cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*

References for CVE-2021-25216

URL Tags
http://www.openwall.com/lists/oss-security/2021/04/29/1 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/2 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/04/29/4 Mailing List Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf Patch Third Party Advisory
https://kb.isc.org/v1/docs/cve-2021-25215 Not Applicable
https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html Mailing List Third Party Advisory
https://security.netapp.com/advisory/ntap-20210521-0006/ Third Party Advisory
https://www.debian.org/security/2021/dsa-4909 Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-657/ Third Party Advisory VDB Entry
cvelogic Threat Intelligence