ISC released BIND 9 fixes covering versions through 9.18.50, 9.20.24, and 9.21.23. Apply them if you run those releases yourself, whether in a small setup or larger environment.Cyber Resilience desk
Sources (1)
- cccs · cccs
What this means for you — CISO:Confirm whether any authoritative or recursive DNS resolvers in your estate run the listed BIND 9 branches and apply the ISC patches on those version lines.
What this means for you — Lean IT orgs:If you run your own BIND DNS servers, update them to a fixed version now; if you use a cloud or registrar DNS service, the provider handles this and you can ignore it.
What this means for you — MSP:Inventory clients on self-hosted BIND 9 (9.11–9.18, 9.20, 9.21, and Supported Preview) and schedule the ISC updates; hosted-DNS clients are out of scope.
What this means for you — Researcher:ISC’s July 22 advisories cover BIND 9.11 through 9.21 and Supported Preview Edition — pull the CVE details and fixed versions from the ISC notices for analysis or detection work.