Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-1519

Опубликовано: 25 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

A flaw was found in BIND. A remote attacker could exploit this vulnerability by sending a maliciously crafted DNSSEC-validated zone to a BIND resolver. This could cause the resolver to consume excessive CPU resources, leading to a denial of service (DoS) for legitimate users.

Отчет

This vulnerability is rated as Important. A flaw in BIND allows a remote attacker to cause a Denial of Service by sending a maliciously crafted DNSSEC-validated zone to a BIND resolver. Red Hat systems running BIND configured for DNSSEC validation are affected. Authoritative-only BIND servers are generally not impacted unless configured to perform recursive queries.

Меры по смягчению последствий

To mitigate this issue, disable DNSSEC validation on affected BIND resolvers. Alternatively, configure the BIND server as authoritative-only if recursive queries are not required. Disabling DNSSEC validation may reduce the security posture of the DNS resolver. A restart of the BIND service (named) is required for these changes to take effect and may temporarily interrupt DNS resolution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-kube-rbac-proxy-rhel9Not affected
Red Hat Enterprise Linux 10bindFixedRHSA-2026:831215.04.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportbindFixedRHSA-2026:2485109.06.2026
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONbindFixedRHSA-2026:1137228.04.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportbindFixedRHSA-2026:1137128.04.2026
Red Hat Enterprise Linux 8bind9.16FixedRHSA-2026:815514.04.2026
Red Hat Enterprise Linux 8bindFixedRHSA-2026:835215.04.2026
Red Hat Enterprise Linux 8bindFixedRHSA-2026:835215.04.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportbindFixedRHSA-2026:1606411.05.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2451305bind: BIND: Denial of Service via maliciously crafted DNSSEC-validated zone

EPSS

Процентиль: 72%
0.01545
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

CVSS3: 7.5
nvd
4 месяца назад

If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU. Authoritative-only servers are generally unaffected, although there are circumstances where authoritative servers may make recursive queries (see: https://kb.isc.org/docs/why-does-my-authoritative-server-make-recursive-queries). This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.46, 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.46-S1, and 9.20.9-S1 through 9.20.20-S1.

CVSS3: 7.5
msrc
4 месяца назад

Excessive NSEC3 iterations cause high CPU load during insecure delegation validation

CVSS3: 7.5
debian
4 месяца назад

If a BIND resolver is performing DNSSEC validation and encounters a ma ...

suse-cvrf
3 месяца назад

Security update for bind

EPSS

Процентиль: 72%
0.01545
Низкий

7.5 High

CVSS3