Missing Release of Resource after Effective Lifetime Affecting bind package, versions [9.20.0,9.20.21)[9.21.0,9.21.20)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.7% (49th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-BIND-15812207
  • published29 Mar 2026
  • disclosed25 Mar 2026
  • creditUnknown

Introduced: 25 Mar 2026

CVE-2026-3104  (opens in a new tab)
CWE-772  (opens in a new tab)

How to fix?

Upgrade bind to version 9.20.21, 9.21.20 or higher.

Overview

Affected versions of this package are vulnerable to Missing Release of Resource after Effective Lifetime via the resolver process. An attacker can exhaust system memory resources by sending specially crafted domain queries over the network, potentially causing service disruption for legitimate users.

Workaround

This vulnerability can be mitigated by restricting access to the resolver to trusted clients only, such as by configuring firewall rules to limit inbound connections to port 53 (UDP/TCP) from authorized IP addresses or networks, or by configuring the service to listen only on specific trusted interfaces or localhost.

CVSS Base Scores

version 4.0
version 3.1