Executive brief
A vulnerability has been identified in BIND 9, a widely used software suite for managing the Domain Name System (DNS) on the internet. An attacker can trick the system into storing incorrect website address information in its memory, a process known as cache poisoning. This could allow an attacker to redirect users to malicious websites or disrupt normal internet traffic for organizations relying on the affected software.
Technical details
A vulnerability exists in BIND 9's handling of DNSSEC-signed responses where an attacker's zone can respond with an RRSIG record containing a smaller number of labels than the zone itself. This discrepancy causes the 'named' process to incorrectly produce a wildcard name for a zone shorter than the attacker's zone. This behavior facilitates cache poisoning, allowing an attacker to inject arbitrary DNS data into the resolver's cache. The vulnerability requires the 'synth-from-dnssec' option to be enabled, which is the default setting. Patches are available in versions 9.20.26, 9.21.24, and 9.20.26-S1.
Affected products
- ISC BIND 9 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23
- ISC BIND 9 Supported Preview Edition 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.24-S1
Timeline
- 2026-07-15: other: Early Notification
- 2026-07-22: advisory: Public disclosure
- 2026-07-22: patched: Fixed versions released