Hide Forgot
As per upstream advisory: Incremental zone transfers (IXFR) provide a way of transferring changed portion(s) of a zone between servers. An IXFR stream containing SOA records with an owner name other than the transferred zone's apex may cause the receiving named server to inadvertently remove the SOA record for the zone in question from the zone database. This leads to an assertion failure when the next SOA refresh query for that zone is made.
Mitigation: Disabling incremental zone transfers (IXFR) by setting "request-ixfr no;" in the desired configuration block (options, zone, or server) prevents the failing assertion from being evaluated.
Acknowledgments: Name: ISC Upstream: Greg Kuechle (SaskTel)
Created attachment 1775847 [details] Patch against 9.11
External References: https://kb.isc.org/docs/cve-2021-25214
Created bind tracking bugs for this issue: Affects: fedora-all [bug 1954897]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2021:3325 https://access.redhat.com/errata/RHSA-2021:3325
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-25214
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4384 https://access.redhat.com/errata/RHSA-2021:4384