7.5
CVE-2026-11605
- EPSS 0.52%
- Veröffentlicht 22.07.2026 14:11:37
- Zuletzt bearbeitet 22.07.2026 20:33:11
- CVE-Watchlists
- Unerledigt
Unnecessary validation of DNSSEC signed records
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but superfluous RRSIG records causes the validator to waste disproportionate CPU time. This issue affects BIND 9 versions 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, and 9.20.9-S1 through 9.20.24-S1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerISC
≫
Produkt
BIND 9
Default Statusunaffected
Version <=
9.20.24
Version
9.20.0
Status
affected
Version <=
9.21.23
Version
9.21.0
Status
affected
Version <=
9.20.24-S1
Version
9.20.9-S1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.413 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| ISC | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-408 Incorrect Behavior Order: Early Amplification
The product allows an entity to perform a legitimate but expensive operation before authentication or authorization has taken place.
https://downloads.isc.org/isc/bind9/9.20.26
https://downloads.isc.org/isc/bind9/9.21.24
https://kb.isc.org/docs/cve-2026-11605