In BIND 9.5.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.11.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch, BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting values for the tkey-gssapi-keytab or tkey-gssapi-credential configuration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. For servers that meet these conditions, the ISC SPNEGO implementation is vulnerable to various attacks, depending on the CPU architecture for which BIND was built: For named binaries compiled for 64-bit platforms, this flaw can be used to trigger a buffer over-read, leading to a server crash. For named binaries compiled for 32-bit platforms, this flaw can be used to trigger a server crash due to a buffer overflow and possibly also to achieve remote code execution. We have determined that standard SPNEGO implementations are available in the MIT and Heimdal Kerberos libraries, which support a broad range of operating systems, rendering the ISC implementation unnecessary and obsolete. Therefore, to reduce the attack surface for BIND users, we will be removing the ISC SPNEGO implementation in the April releases of BIND 9.11 and 9.16 (it had already been dropped from BIND 9.17). We would not normally remove something from a stable ESV (Extended Support Version) of BIND, but since system libraries can replace the ISC SPNEGO implementation, we have made an exception in this case for reasons of stability and security.
Conclusion & alert: CVE-2021-25216 is rated High Risk (72.3/100): CVSS High severity, with high exploitation likelihood (EPSS 83.41%, 100th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +55.66% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 27.74% | 83.41% | +55.66% |
| 2 | 2026-03-04 | 61.24% | 27.74% | -33.49% |
| 3 | 2026-03-01 | — | 61.24% | — |
Full EPSS history (74 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.2 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
critical | CVE-2021-25216: 1 source package rows (bind); 10 state rows across 10 repos (3.10-main, 3.11-main, 3.12-main, 3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 10, open 0. | https://security.alpinelinux.org/vuln/CVE-2021-25216 |
debian
|
not yet assigned | CVE-2021-25216 not yet assigned priority: Debian including 1 source packages (bind9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2021-25216 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2021-25216 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2021-25216/ |
ubuntu
|
medium | CVE-2021-25216 medium priority: Ubuntu including 1 source packages (bind9), 15 status rows across 15 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, trusty, upstream, xenial): released 15. | https://ubuntu.com/security/CVE-2021-25216 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| isc | bind | >= 9.0.0, < 9.11.31 | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* |
| isc | bind | >= 9.12.0, < 9.16.15 | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* |
| isc | bind | >= 9.17.0, < 9.17.12 | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* |
| isc | bind | 9.9.3 | cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.9.12 | cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.9.13 | cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.10.5 | cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.10.7 | cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.3 | cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.5 | cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.5 | cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.5 | cpe:2.3:a:isc:bind:9.11.5:s6:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.6 | cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.7 | cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.8 | cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.12 | cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.21 | cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.27 | cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.29 | cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.16.8 | cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.16.11 | cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.16.13 | cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:* |
| siemens | sinec_infrastructure_network_services | < 1.0.1.1 | cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:* |
| netapp | active_iq_unified_manager | — | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vsphere:*:* |
| netapp | cloud_backup | — | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* |
| netapp | aff_a250_firmware | — | cpe:2.3:o:netapp:aff_a250_firmware:-:*:*:*:*:*:*:* |
| netapp | aff_500f_firmware | — | cpe:2.3:o:netapp:aff_500f_firmware:-:*:*:*:*:*:*:* |
| netapp | h300s_firmware | — | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
| netapp | h500s_firmware | — | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
| netapp | h700s_firmware | — | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
| netapp | h300e_firmware | — | cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:* |
| netapp | h500e_firmware | — | cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:* |
| netapp | h700e_firmware | — | cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:* |
| netapp | h410s_firmware | — | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2021/04/29/1 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2021/04/29/2 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2021/04/29/3 | Mailing List Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2021/04/29/4 | Mailing List Third Party Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | Patch Third Party Advisory |
| https://kb.isc.org/v1/docs/cve-2021-25215 | Not Applicable |
| https://lists.debian.org/debian-lts-announce/2021/05/msg00001.html | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20210521-0006/ | Third Party Advisory |
| https://www.debian.org/security/2021/dsa-4909 | Third Party Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-21-657/ | Third Party Advisory VDB Entry |