CVE-2026-77119
- EPSS 0.19%
- Veröffentlicht 16.09.2026 14:17:11
- Zuletzt bearbeitet 17.09.2026 19:16:59
A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20...
CVE-2026-75029
- EPSS 0.41%
- Veröffentlicht 16.09.2026 14:15:12
- Zuletzt bearbeitet 17.09.2026 19:16:58
In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can cause increase...
CVE-2026-19033
- EPSS 0.2%
- Veröffentlicht 16.09.2026 14:10:08
- Zuletzt bearbeitet 17.09.2026 18:16:38
For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG...
CVE-2026-19666
- EPSS 0.48%
- Veröffentlicht 16.09.2026 14:02:30
- Zuletzt bearbeitet 17.09.2026 18:16:39
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 th...
CVE-2026-78301
- EPSS 0.18%
- Veröffentlicht 16.09.2026 13:58:11
- Zuletzt bearbeitet 17.09.2026 19:16:59
A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker inserts a malformed zone into a BIND authoritative server (e.g., via zone transfer), queries for names inside the configured zone th...
CVE-2026-19662
- EPSS 0.41%
- Veröffentlicht 16.09.2026 13:50:10
- Zuletzt bearbeitet 17.09.2026 19:16:41
An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds...
CVE-2026-19667
- EPSS 0.49%
- Veröffentlicht 16.09.2026 13:46:56
- Zuletzt bearbeitet 17.09.2026 19:16:41
If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This issue affects BI...
CVE-2026-13321
- EPSS 0.26%
- Veröffentlicht 22.07.2026 14:16:10
- Zuletzt bearbeitet 22.07.2026 20:33:11
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9....
CVE-2026-13204
- EPSS 0.67%
- Veröffentlicht 22.07.2026 14:15:30
- Zuletzt bearbeitet 22.07.2026 20:33:11
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 ve...
CVE-2026-12617
- EPSS 0.52%
- Veröffentlicht 22.07.2026 14:14:46
- Zuletzt bearbeitet 22.07.2026 20:33:11
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the autho...