PatchSiren

PatchSiren cyber security CVE debrief

CVE-2016-6171 Knot Dns CVE debrief

CVE-2016-6171 is a high-severity availability issue in Knot DNS before 2.3.0. A remote DNS server can trigger memory exhaustion and crash a slave server by causing a large zone transfer through DDNS, AXFR, or IXFR. The issue was published by NVD on 2017-02-09 and later updated on 2026-05-13.

Vendor
Knot Dns
Product
Unknown
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2017-02-09
Original CVE updated
2026-05-13
Advisory published
2017-02-09
Advisory updated
2026-05-13

Who should care

Operators of Knot DNS deployments, especially slave/secondary DNS servers and teams handling zone transfers (AXFR/IXFR) or dynamic DNS updates (DDNS), should prioritize this issue. Any environment that accepts transfers from remote DNS peers may be exposed to denial-of-service risk.

Technical summary

NVD lists the vulnerable version range as Knot DNS versions before 2.3.0. The weakness is classified as CWE-400 (Uncontrolled Resource Consumption). The reported impact is remote denial of service: large zone transfers can consume memory until the slave server crashes. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H, indicating network reachability, low attack complexity, no privileges or user interaction, and high availability impact.

Defensive priority

High. This is a remotely reachable availability risk with no privileges or user interaction required, and it can take down DNS service components that depend on Knot DNS slave behavior.

Recommended defensive actions

  • Upgrade Knot DNS to version 2.3.0 or later, which is the first version outside the vulnerable range listed by NVD.
  • Review and restrict zone-transfer and dynamic DNS exposure where possible, especially from untrusted or broad network sources.
  • Monitor secondary DNS servers for abnormal memory growth or crashes around transfer activity.
  • Validate whether internal tooling or automation can generate unusually large zone transfers and set operational safeguards.
  • Check vendor release notes and advisories for any additional hardening guidance related to transfer handling.

Evidence notes

The NVD record identifies the affected product as knot-dns and marks versions before 2.3.0 as vulnerable. The NVD reference set includes vendor and technical materials, including Knot release notes, a vendor issue tracker entry, and an operational mailing-list description. The vulnerability is mapped to CWE-400 and scored HIGH with CVSS 8.6.

Sources and references

Verified primary and authoritative sources

  • CVE-2016-6171 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2016-6171

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2016-6171 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2016-6171

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.