CVE-2026-10822

Summary

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit.

BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify a PRIVATEDNS algorithm (253), and in the algorithm identifier, improperly give a length longer than the actual identifier data. The invalid identifier will be stored. If BIND later needs to render that record to text, it will use the invalid length during processing, leading to a consistency check failing. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Affected Software

VendorProductVersion RangeStatus
ISCBIND 99.18.0 <= 9.18.50affected
ISCBIND 99.20.0 <= 9.20.24affected
ISCBIND 99.21.0 <= 9.21.23affected
ISCBIND 99.18.11-S1 <= 9.18.50-S1affected
ISCBIND 99.20.9-S1 <= 9.20.24-S1affected

Weaknesses

  • CWE-617: CWE-617 Reachable Assertion
  • CWE-1284: CWE-1284 Improper Validation of Specified Quantity in Input

Workarounds

No workarounds known.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References