Executive brief
BIND is a widely used software for managing Domain Name System (DNS) services, often integrated with Active Directory or Kerberos environments. A vulnerability exists where an attacker can send specially crafted network packets that cause the server to consume excessive amounts of memory without releasing it. If left unaddressed, this can lead to a complete service outage, preventing users from accessing websites or internal network resources.
Technical details
A memory leak vulnerability (CWE-771) exists in BIND 9 when processing TKEY-based authentication via GSS-API tokens. The root cause is a failure to release allocated memory when receiving maliciously constructed packets during GSS-API TKEY negotiation. This is a remote, unauthenticated attack vector that allows an attacker to trigger excessive memory consumption. Over time, or with sufficient volume, the 'named' process will exhaust available system memory and fail, resulting in a denial of service. Patches are available in versions 9.18.49, 9.20.23, and 9.21.22.
Affected products
- ISC BIND 9 9.0.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21
- ISC BIND 9 Supported Preview Edition 9.9.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, 9.20.9-S1 through 9.20.22-S1
Timeline
- 2026-05-13: other: Early notification provided
- 2026-05-20: advisory: Public disclosure by ISC
- 2026-05-20: patched: Patched versions released