Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19033

Опубликовано: 16 сент. 2026
Источник: redhat
CVSS3: 6.5

Описание

For a secondary zone with transfers restricted by TSIG, named may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, named does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

A flaw was found in bind. A remote attacker without a valid TSIG (Transaction Signature) can send unauthorized zone contents to a secondary server during a multi-message TCP IXFR (Incremental Zone Transfer). The named process may apply this unauthenticated data before the TSIG signature is verified. If the signature never arrives, named does not revert to its previous state, leading to the serving of unauthorized zone data and compromising information integrity.

Отчет

Moderate: This vulnerability allows an attacker to provide unauthorized zone content to a secondary BIND server if it is configured for multi-message TCP IXFR transfers with TSIG restrictions. While TSIG is intended to secure zone transfers, the flaw prevents named from rolling back changes when a valid signature is not received, leading to potential data integrity issues.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindFix deferred
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindFix deferred
Red Hat Enterprise Linux 8bindFix deferred
Red Hat Enterprise Linux 8bind9.16Fix deferred
Red Hat Enterprise Linux 9bindFix deferred
Red Hat Enterprise Linux 9bind9.18Fix deferred
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Hardened ImagesbindAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2535479bind: BIND: Unauthorized zone content updates via unauthenticated IXFR deltas

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

(For a secondary zone with transfers restricted by TSIG, `named` may st ...)

CVSS3: 6.5
nvd
5 дней назад

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

CVSS3: 6.5
debian
5 дней назад

For a secondary zone with transfers restricted by TSIG, `named` may st ...

CVSS3: 6.5
github
5 дней назад

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess a valid TSIG signature to send unauthorized zone contents to a secondary server. Although no TSIG signature ever arrives, `named` does not rollback to the pre-transfer state. To exploit the vulnerability, the transfer must be a multi-message TCP IXFR, as described by RFC 8945. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

6.5 Medium

CVSS3