Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19666

Опубликовано: 16 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

On a resolver configured to use dns64, if an applicable answer from the authoritative server is malformed in a specific way, the resolver named process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

A flaw was found in BIND. When a resolver is configured to use DNS64, a specially crafted, malformed answer from an authoritative server can cause the named process to exit unexpectedly. This can lead to a Denial of Service (DoS) for clients relying on the affected resolver.

Отчет

Important: This denial of service vulnerability affects BIND resolvers configured to use the dns64 feature. A specially crafted malformed DNS64 response from an authoritative server can cause the named process to unexpectedly terminate, leading to service unavailability. Exploitation requires the dns64 feature to be explicitly enabled in the resolver's configuration.

Меры по смягчению последствий

To mitigate this issue, disable the dns64 feature in the BIND resolver configuration if it is not required. This can be done by removing or commenting out the dns64 configuration block in named.conf or related configuration files. After modifying the configuration, the BIND service (named) must be reloaded or restarted for the changes to take effect. This action may temporarily interrupt DNS resolution services.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindAffected
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindAffected
Red Hat Enterprise Linux 8bindAffected
Red Hat Enterprise Linux 8bind9.16Affected
Red Hat Enterprise Linux 9bindAffected
Red Hat Enterprise Linux 9bind9.18Affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Hardened ImagesbindAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2535477bind: BIND: Denial of Service via malformed DNS64 responses

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

(On a resolver configured to use ``dns64``, if an applicable answer fro ...)

CVSS3: 7.5
nvd
4 дня назад

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

CVSS3: 7.5
debian
4 дня назад

On a resolver configured to use ``dns64``, if an applicable answer fro ...

CVSS3: 7.5
github
4 дня назад

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

7.5 High

CVSS3