Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13321

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.

Отчет

An attacker controlling any DNSSEC-signed zone can craft NSEC records that span into victim zones, enabling cross-zone cache poisoning with authenticated denial-of-service responses (AD=1).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindAffected
Red Hat Enterprise Linux 6bindAffected
Red Hat Enterprise Linux 7bindAffected
Red Hat Enterprise Linux 8bindAffected
Red Hat Enterprise Linux 8bind9.16Affected
Red Hat Enterprise Linux 9bindAffected
Red Hat Enterprise Linux 9bind9.18Affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Hardened ImagesbindAffected
Red Hat OpenShift Container Platform 4rhcosAffected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2504166bind: bind9: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field

EPSS

Процентиль: 12%
0.00217
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
21 день назад

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 8.6
nvd
21 день назад

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 8.6
msrc
5 дней назад

DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field

CVSS3: 8.6
debian
21 день назад

The BIND resolver accepts validly-signed NSEC records where the "Next ...

CVSS3: 8.6
github
21 день назад

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

EPSS

Процентиль: 12%
0.00217
Низкий

8.6 High

CVSS3