Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19668

Опубликовано: 16 сент. 2026
Источник: redhat
CVSS3: 5.3

Описание

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

A flaw was found in BIND, a widely used Domain Name System (DNS) software. A remote attacker could exploit this vulnerability by sending a large number of specially crafted, invalid DNSSEC (Domain Name System Security Extensions) records to a BIND recursive resolver. This could lead to excessive resource consumption, resulting in a Denial of Service (DoS) for the affected resolver.

Отчет

This Moderate impact flaw in BIND recursive resolvers can lead to a denial of service due to excessive resource consumption when processing specific invalid DNSSEC records. Red Hat's default BIND configurations include max-records-per-type and max-types-per-name limits, which help reduce the exposure and prevent a more severe impact.

Меры по смягчению последствий

To mitigate potential denial of service, ensure that the BIND recursive resolver's configuration includes appropriate limits for max-records-per-type and max-types-per-name within the named.conf file. These settings help control resource consumption when encountering invalid DNSSEC records. A restart of the named service is required for any configuration changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindFix deferred
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindFix deferred
Red Hat Enterprise Linux 8bindFix deferred
Red Hat Enterprise Linux 8bind9.16Fix deferred
Red Hat Enterprise Linux 9bindFix deferred
Red Hat Enterprise Linux 9bind9.18Fix deferred
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Hardened ImagesbindAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2535476bind: BIND: Denial of Service via invalid DNSSEC records

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 дня назад

(A BIND recursive resolver may experience excessive resource consumptio ...)

CVSS3: 5.3
nvd
4 дня назад

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

CVSS3: 5.3
debian
4 дня назад

A BIND recursive resolver may experience excessive resource consumptio ...

CVSS3: 5.3
github
4 дня назад

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the exposure. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

5.3 Medium

CVSS3