Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19941

Опубликовано: 16 сент. 2026
Источник: redhat
CVSS3: 5.9

Описание

An inapplicable NSEC record may be accepted by a named resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

A flaw was found in BIND 9. A remote attacker could exploit this by providing an inapplicable NSEC (Next Secure) record to a named resolver. This could allow the attacker to mask the existence of a victim's wildcard DNS (Domain Name System) record, potentially leading to a misrepresentation of DNS information.

Отчет

This Moderate impact flaw in BIND 9 allows a remote attacker to mask the existence of DNS wildcard records by providing specially crafted NSEC records to a named resolver. While the attack complexity is high, successful exploitation could lead to a misrepresentation of DNS information, potentially affecting services relying on accurate DNS resolution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindFix deferred
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindFix deferred
Red Hat Enterprise Linux 8bindFix deferred
Red Hat Enterprise Linux 8bind9.16Fix deferred
Red Hat Enterprise Linux 9bindFix deferred
Red Hat Enterprise Linux 9bind9.18Fix deferred
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Hardened ImagesbindAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2535457bind9: bind: BIND 9: DNS wildcard record existence can be masked by an attacker via inapplicable NSEC records

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
4 дня назад

(An inapplicable NSEC record may be accepted by a `named` resolver as p ...)

CVSS3: 5.9
nvd
4 дня назад

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

CVSS3: 5.9
debian
4 дня назад

An inapplicable NSEC record may be accepted by a `named` resolver as p ...

CVSS3: 5.9
github
4 дня назад

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.

5.9 Medium

CVSS3