Junglewise Threat Intelligence

CVE-2026-11605: ISC BIND 9 resource exhaustion in DNSSEC validation

CVE-2026-11605 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Isc BIND 9. Vendors: Isc.

Executive brief

A resource exhaustion vulnerability exists in BIND 9, a widely used software for translating domain names into IP addresses. An attacker can send a specially crafted DNS query that forces the server to perform excessive and unnecessary security checks, consuming high amounts of CPU power. This can lead to a denial-of-service, making the DNS server slow or completely unresponsive to legitimate user requests.

Technical details

A resource exhaustion vulnerability exists in BIND 9's DNSSEC validation logic. The resolver incorrectly attempts to validate all RRSIG records provided in an answer, even those that are not required for a successful validation. By querying an authoritative server that returns a large number of valid but unnecessary RRSIG records, a remote attacker can cause the BIND validator to consume disproportionate CPU resources. This is classified as an early amplification/incorrect behavior order issue (CWE-408). Patches are available in versions 9.20.26, 9.21.24, and 9.20.26-S1.

Affected products

  • ISC BIND 9 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.20.9-S1 through 9.20.24-S1

Timeline

  • 2026-07-15: other: Early notification provided
  • 2026-07-22: disclosed: Public disclosure
  • 2026-07-22: patched: Patched versions 9.20.26 and 9.21.24 released

References

Related threats