Executive brief
BIND 9 is a widely used software suite for managing Domain Name System (DNS) services. A vulnerability in its resolver component allows an attacker to cause a memory leak by requesting information about a specially crafted domain. Over time, this can exhaust the server's available memory, leading to a service crash or system instability, effectively knocking the DNS server offline.
Technical details
A memory leak exists in BIND 9 within the code responsible for preparing DNSSEC proofs of non-existence. The vulnerability is classified as a missing release of memory (CWE-401/CWE-772) and can be triggered remotely by an unauthenticated attacker who sends a query for a specially crafted domain to an affected BIND resolver. This results in unbounded growth of Resident Set Size (RSS) memory, eventually causing an out-of-memory (OOM) condition. Additionally, the 'named' process will exit with an assertion failure if a shutdown or reload is attempted while in this state. Authoritative-only servers are generally unaffected. Patches are available in versions 9.20.21 and 9.21.20.
Affected products
- ISC BIND 9 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.20.9-S1 through 9.20.20-S1
Timeline
- 2026-03-18: other: Early notification provided
- 2026-03-25: disclosed: Public disclosure and advisory published
- 2026-03-25: patched: Patched versions 9.20.21 and 9.21.20 released