Executive brief
BIND, a widely used system for translating website names into IP addresses, is vulnerable to a resource exhaustion attack. An attacker can create a malicious DNS zone that, when queried by a BIND resolver, causes the system to consume excessive processing power or memory. This can lead to significant performance degradation or a denial of service for users relying on that DNS server.
Technical details
BIND 9 resolvers are susceptible to a Denial of Service (DoS) vulnerability classified as Early Amplification (CWE-408). The vulnerability is triggered when a resolver attempts to process queries for a specially crafted malicious DNS zone. This results in disproportionate resource consumption (CPU or memory) relative to the query size. The attack can be launched remotely over the network without authentication. ISC has released patches in versions 9.18.49, 9.20.23, and 9.21.22 to address this issue.
Affected products
- ISC BIND 9 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, 9.20.9-S1 through 9.20.22-S1
Timeline
- 2026-05-20: disclosed
- 2026-05-20: patched
- 2026-05-20: advisory