CVE-2026-11721
- EPSS 0.55%
- Veröffentlicht 22.07.2026 14:13:08
- Zuletzt bearbeitet 22.07.2026 20:33:11
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's...
CVE-2026-11605
- EPSS 0.67%
- Veröffentlicht 22.07.2026 14:11:37
- Zuletzt bearbeitet 22.07.2026 20:33:11
The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if they are not strictly needed. A query to an authoritative server/zone which returns many valid but super...
CVE-2026-11331
- EPSS 0.54%
- Veröffentlicht 22.07.2026 14:10:44
- Zuletzt bearbeitet 22.07.2026 20:33:11
An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ...
CVE-2026-10822
- EPSS 0.54%
- Veröffentlicht 22.07.2026 14:09:57
- Zuletzt bearbeitet 22.07.2026 20:33:11
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDN...
CVE-2026-10723
- EPSS 0.27%
- Veröffentlicht 22.07.2026 14:08:19
- Zuletzt bearbeitet 22.07.2026 20:33:11
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1...
CVE-2026-5946
- EPSS 1.87%
- Veröffentlicht 20.05.2026 13:16:40
- Zuletzt bearbeitet 17.09.2026 12:18:24
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Special...
CVE-2026-5947
- EPSS 1.39%
- Veröffentlicht 20.05.2026 13:16:40
- Zuletzt bearbeitet 24.08.2026 13:19:13
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. If, during that validation, the "recursive-clients"...
CVE-2026-5950
- EPSS 0.66%
- Veröffentlicht 20.05.2026 13:16:40
- Zuletzt bearbeitet 23.07.2026 12:10:00
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger specific retry conditions. T...
CVE-2026-3039
- EPSS 1.05%
- Veröffentlicht 20.05.2026 13:16:23
- Zuletzt bearbeitet 17.09.2026 12:18:14
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typically these servers will be found in Active Direct...
CVE-2026-3592
- EPSS 0.41%
- Veröffentlicht 20.05.2026 13:16:23
- Zuletzt bearbeitet 24.07.2026 10:10:00
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources. This issue affects BIND 9 versions 9.11.0 thr...