Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19662

Опубликовано: 16 сент. 2026
Источник: redhat
CVSS3: 5.9

Описание

An attacker may be able to cause a named resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the named resolver will encounter a use-after-free bug, and abort. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

A flaw was found in BIND 9. A remote attacker can cause a named resolver to stop functioning (Denial of Service) by inducing the victim resolver to send multiple queries for a DNSSEC-signed zone. If the attacker's authoritative server responds with a specific sequence of crafted answers that arrive with particular timing, a use-after-free vulnerability is triggered, leading to the resolver's abortion.

Отчет

This Moderate impact denial of service vulnerability in BIND 9's named resolver can lead to service unavailability. Exploitation requires an attacker to operate an authoritative DNS server and specifically induce a vulnerable resolver to query it for a DNSSEC-signed zone. The attack relies on a precise sequence and timing of crafted DNSSEC responses, limiting its broader applicability.

Меры по смягчению последствий

To mitigate this issue, consider disabling DNSSEC validation on named resolvers if it is not a strict requirement for your environment. This can be achieved by setting dnssec-validation no; in the named.conf file. Disabling DNSSEC validation will prevent the resolver from processing DNSSEC-signed zones, thereby avoiding this specific vulnerability, but it will also remove the security benefits provided by DNSSEC. After modifying the configuration, the named service must be reloaded or restarted for the changes to take effect. sudo systemctl reload named sudo systemctl restart named

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindFix deferred
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindFix deferred
Red Hat Enterprise Linux 8bindFix deferred
Red Hat Enterprise Linux 8bind9.16Fix deferred
Red Hat Enterprise Linux 9bindFix deferred
Red Hat Enterprise Linux 9bind9.18Fix deferred
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Hardened ImagesbindAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2535445bind9: bind: BIND 9: Denial of Service via crafted DNSSEC responses

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 дня назад

(An attacker may be able to cause a `named` resolver to abort. The atta ...)

CVSS3: 5.9
nvd
5 дней назад

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

CVSS3: 5.9
debian
5 дней назад

An attacker may be able to cause a `named` resolver to abort. The atta ...

CVSS3: 5.9
github
4 дня назад

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

5.9 Medium

CVSS3