Executive brief
BIND 9, a widely used software for translating human-readable domain names into IP addresses, is vulnerable to a denial-of-service attack. An attacker can overwhelm the system with specific types of security-signed requests, causing the server to consume massive amounts of memory far beyond its configured limits. This can lead to system instability, slow response times, or a complete service outage, disrupting internet connectivity for users relying on the affected server.
Technical details
A vulnerability in BIND 9's DNSSEC validation logic allows for uncontrolled resource consumption (CWE-770). When a validating resolver is targeted by a random subdomain attack against a DNSSEC-signed zone, and the incoming query rate exceeds the resolver's validation throughput, memory usage can grow orders of magnitude beyond the 'max-cache-size' limit. This is a remote, unauthenticated attack vector that results in a denial-of-service (DoS) condition. The issue is resolved in BIND versions 9.20.26, 9.21.24, and 9.20.26-S1.
Affected products
- ISC BIND 9 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.24-S1
Timeline
- 2026-07-15: other: Early Notification
- 2026-07-22: advisory: Public disclosure and NVD publication
- 2026-07-22: patched: Patched versions 9.20.26 and 9.21.24 released