Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-11331

Опубликовано: 22 июл. 2026
Источник: debian
EPSS Низкий

Описание

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
bind9fixed1:9.20.26-1package

Примечания

  • https://kb.isc.org/docs/cve-2026-11331

  • https://gitlab.isc.org/isc-projects/bind9/-/commit/e1c83d27984f10ff929bc54d6ed84b5152be96d5 (9.16-branch)

  • https://gitlab.isc.org/isc-projects/bind9/-/commit/25b572a6d00f717d7992f154f28b43d2b2ffd0b3 (9.16-branch)

  • https://gitlab.isc.org/isc-projects/bind9/-/commit/ee2ac186bc5f75f7f3f7049f1a21e9a2014cee59 (9.16-branch)

  • https://gitlab.isc.org/isc-projects/bind9/-/commit/adc8285d23e2eac6ec463f5dbc5a9596fdd36c60 (9.18-branch)

  • https://gitlab.isc.org/isc-projects/bind9/-/commit/095b11f20f911f5b8059bdc349b256d6c64ece30 (9.18-branch)

  • https://gitlab.isc.org/isc-projects/bind9/-/commit/dc328a199f96222e0c30cc20b7b795bfc2c9b2e4 (9.18-branch)

EPSS

Процентиль: 34%
0.00416
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
23 дня назад

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
redhat
23 дня назад

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
nvd
23 дня назад

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

msrc
20 дней назад

Potential wildcard CNAME RPZ policy bypass

CVSS3: 7.5
github
23 дня назад

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG error condition during RPZ processing. This is not handled correctly and may lead to defeating the RPZ rule. It also may lead to an unexpected exit of the BIND 9 software. This issue affects BIND 9 versions 9.16.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.16.8-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

EPSS

Процентиль: 34%
0.00416
Низкий