Junglewise Threat Intelligence

CVE-2026-11622: ISC BIND 9 resource exhaustion in DNSSEC validating resolver

CVE-2026-11622 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Isc BIND 9. Vendors: Isc.

Executive brief

BIND 9, a widely used software for translating human-readable domain names into IP addresses, is vulnerable to a denial-of-service attack. An attacker can overwhelm the system with specific types of security-signed requests, causing the server to consume massive amounts of memory far beyond its configured limits. This can lead to system instability, slow response times, or a complete service outage, disrupting internet connectivity for users relying on the affected server.

Technical details

A vulnerability in BIND 9's DNSSEC validation logic allows for uncontrolled resource consumption (CWE-770). When a validating resolver is targeted by a random subdomain attack against a DNSSEC-signed zone, and the incoming query rate exceeds the resolver's validation throughput, memory usage can grow orders of magnitude beyond the 'max-cache-size' limit. This is a remote, unauthenticated attack vector that results in a denial-of-service (DoS) condition. The issue is resolved in BIND versions 9.20.26, 9.21.24, and 9.20.26-S1.

Affected products

  • ISC BIND 9 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.24-S1

Timeline

  • 2026-07-15: other: Early Notification
  • 2026-07-22: advisory: Public disclosure and NVD publication
  • 2026-07-22: patched: Patched versions 9.20.26 and 9.21.24 released

References

Related threats