Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10723

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses.

Отчет

This Moderate flaw in BIND allows an attacker to forge authenticated NXDOMAIN responses for sibling zones due to incorrect validation of child-zone NSEC3 records. Exploitation requires high attack complexity, limiting the immediate risk to Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindAffected
Red Hat Enterprise Linux 6bindAffected
Red Hat Enterprise Linux 7bindAffected
Red Hat Enterprise Linux 8bindAffected
Red Hat Enterprise Linux 8bind9.16Affected
Red Hat Enterprise Linux 9bindAffected
Red Hat Enterprise Linux 9bind9.18Affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Hardened Imagesbind-main-9.20.26-0.1.hum1FixedRHSA-2026:5407112.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-345
https://bugzilla.redhat.com/show_bug.cgi?id=2504560bind: bind9: Incorrect acceptance of NSEC3 records

EPSS

Процентиль: 18%
0.00266
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
ubuntu
23 дня назад

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 6.8
nvd
23 дня назад

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 6.8
msrc
21 день назад

Incorrect acceptance of NSEC3 records

CVSS3: 6.8
debian
23 дня назад

BIND may accept incorrect child-zone NSEC3 records as valid, which cou ...

CVSS3: 6.8
github
23 дня назад

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

EPSS

Процентиль: 18%
0.00266
Низкий

6.8 Medium

CVSS3