Junglewise Threat Intelligence

CVE-2026-11721: ISC BIND 9 cache poisoning via RRSIG label count discrepancy

CVE-2026-11721 · Severity: high · CVSS 7.5 · Published 2026-07-22

Technologies: Isc BIND 9 Supported Preview Edition, Isc BIND 9. Vendors: Isc.

Executive brief

A vulnerability has been identified in BIND 9, a widely used software suite for managing the Domain Name System (DNS) on the internet. An attacker can trick the system into storing incorrect website address information in its memory, a process known as cache poisoning. This could allow an attacker to redirect users to malicious websites or disrupt normal internet traffic for organizations relying on the affected software.

Technical details

A vulnerability exists in BIND 9's handling of DNSSEC-signed responses where an attacker's zone can respond with an RRSIG record containing a smaller number of labels than the zone itself. This discrepancy causes the 'named' process to incorrectly produce a wildcard name for a zone shorter than the attacker's zone. This behavior facilitates cache poisoning, allowing an attacker to inject arbitrary DNS data into the resolver's cache. The vulnerability requires the 'synth-from-dnssec' option to be enabled, which is the default setting. Patches are available in versions 9.20.26, 9.21.24, and 9.20.26-S1.

Affected products

  • ISC BIND 9 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23
  • ISC BIND 9 Supported Preview Edition 9.11.3-S1 through 9.18.50-S1, 9.20.9-S1 through 9.20.24-S1

Timeline

  • 2026-07-15: other: Early Notification
  • 2026-07-22: advisory: Public disclosure
  • 2026-07-22: patched: Fixed versions released

References

Related threats