---
id: CVE-2020-8619
title: >-
  In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND
  9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1:
  Unless a nameserver is providing authoritative service for one or more zones
  and at le…
summary: >-
  In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND
  9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1:
  Unless a nameserver is providing authoritative service for one or more zones
  and at le…
severity: medium
cvss: 4.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-404
vendor: isc
product: bind
affected:
  - 'bind >= 9.11.14, <= 9.11.19'
  - 'bind >= 9.11.14-s1, <= 9.11.19-s1'
  - 'bind >= 9.14.9, <= 9.14.12'
  - 'bind >= 9.16.0, <= 9.16.3'
  - fedora = 31
  - fedora = 32
  - leap = 15.1
  - leap = 15.2
  - debian_linux = 10.0
  - ubuntu_linux = 20.04
  - steelstore_cloud_integrated_storage
published: '2020-06-17'
updated: '2026-09-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-8619'
references:
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html'
    label: security-officer@isc.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html'
    label: security-officer@isc.org
  - url: 'https://kb.isc.org/docs/cve-2020-8619'
    label: security-officer@isc.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/
    label: security-officer@isc.org
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/
    label: security-officer@isc.org
  - url: 'https://security.netapp.com/advisory/ntap-20200625-0003/'
    label: security-officer@isc.org
  - url: 'https://usn.ubuntu.com/4399-1/'
    label: security-officer@isc.org
  - url: 'https://www.debian.org/security/2020/dsa-4752'
    label: security-officer@isc.org
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://kb.isc.org/docs/cve-2020-8619'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNFTTYJ5JJJJ6QG3AHXJGDIIEYMDFWFW/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EIOXMJX4N3LBKC65OXNBE52W4GAS7QEX/
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20200625-0003/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://usn.ubuntu.com/4399-1/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2020/dsa-4752'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02105
epssPercentile: 0.80663
ingestedAt: '2026-09-01T21:32:40.258Z'
---

## Overview

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be encountered. A would-be attacker who is allowed to change zone content could theoretically introduce such a record in order to exploit this condition to cause denial of service, though we consider the use of this vector unlikely because any such attack would require a significant privilege level and be easily traceable.

## Affected

- `bind >= 9.11.14, <= 9.11.19`
- `bind >= 9.11.14-s1, <= 9.11.19-s1`
- `bind >= 9.14.9, <= 9.14.12`
- `bind >= 9.16.0, <= 9.16.3`
- `fedora = 31`
- `fedora = 32`
- `leap = 15.1`
- `leap = 15.2`
- `debian_linux = 10.0`
- `ubuntu_linux = 20.04`
- `steelstore_cloud_integrated_storage`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
