Executive brief
ISC BIND 9, a widely used DNS server suite, is vulnerable to a race condition that can cause the service to crash. An attacker can trigger this by sending specific DNS messages during a high-traffic query flood, potentially leading to a denial-of-service (DoS) condition. This impact can disrupt internet connectivity or internal network name resolution for organizations relying on affected versions.
Technical details
A race condition exists in BIND 9's handling of SIG(0) signed DNS messages. When BIND receives such a message, it initiates signature validation; however, if the 'recursive-clients' limit is reached simultaneously (e.g., during a query flood), the message may be discarded while the validation process still attempts to read it. This results in a use-after-free (UAF) violation. An unauthenticated remote attacker can exploit this to cause the BIND process to abort with a segmentation violation, resulting in a denial-of-service. The vulnerability affects both authoritative servers and resolvers. Patches are available in versions 9.20.23 and 9.21.22.
Affected products
- ISC BIND 9 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.20.9-S1 through 9.20.22-S1
Timeline
- 2026-05-13: other: Early Notification
- 2026-05-20: advisory: Public disclosure by ISC
- 2026-05-20: patched: Fixed versions 9.20.23 and 9.21.22 released