CVE-2026-19662
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
An attacker may be able to cause a named resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the named resolver will encounter a use-after-free bug, and abort.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ISC | BIND 9 | 9.11.0 <= 9.18.50 | affected |
| ISC | BIND 9 | 9.20.0 <= 9.20.27 | affected |
| ISC | BIND 9 | 9.11.3-S1 <= 9.18.50-S1 | affected |
| ISC | BIND 9 | 9.20.9-S1 <= 9.20.27-S1 | affected |
Weaknesses
- CWE-416: CWE-416 Use After Free
Workarounds
No workarounds known.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.