A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
BIND DNS servers using GSS-TSIG authentication are vulnerable to crashes and potentially remote code execution through a buffer overflow in SPNEGO negotiation. This affects servers explicitly configured with GSSAPI options, commonly found in networks integrating BIND with Samba or Active Directory.
A buffer overflow vulnerability exists in BIND's SPNEGO implementation used for GSS-TSIG authentication. The attack vector requires a server configured with tkey-gssapi-keytab or tkey-gssapi-credential options; on 64-bit platforms it causes denial of service via buffer over-read, while 32-bit platforms are vulnerable to both DoS and potential RCE through buffer overflow.