Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3119

Опубликовано: 25 мар. 2026
Источник: redhat
CVSS3: 6.5

Описание

Under certain conditions, named may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the named configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

A flaw was found in BIND, specifically within the named daemon. An authenticated remote attacker, possessing a valid Transaction Signature (TSIG) key configured on the server, could send a specially crafted query containing a TKEY record. This action may cause the named daemon to crash, leading to a Denial of Service (DoS) for the affected DNS service.

Отчет

Moderate impact. A flaw in BIND 9's named component can lead to a Denial of Service if an attacker with a valid Transaction Signature (TSIG) key sends a specially crafted query. Red Hat Enterprise Linux 8 and 9 are affected by this vulnerability.

Меры по смягчению последствий

To mitigate this issue, restrict access to the named service to only trusted networks and clients. If Transaction Signature (TSIG) keys are not actively used or required, consider disabling them in the BIND configuration. If TSIG keys are necessary, ensure they are securely managed and only distributed to authorized clients. After making configuration changes, a restart of the named service may be required to apply the changes, which could temporarily impact DNS resolution.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindFix deferred
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected
Red Hat Enterprise Linux 8bind9.16Not affected
Red Hat Enterprise Linux 9bindNot affected
Red Hat Enterprise Linux 9bind9.18Not affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesbind-main-9.18.48-1.hum1FixedRHSA-2026:693507.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-237
https://bugzilla.redhat.com/show_bug.cgi?id=2451308bind: BIND: Denial of Service via authenticated TKEY queries

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
5 месяцев назад

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

CVSS3: 6.5
nvd
5 месяцев назад

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

CVSS3: 6.5
msrc
4 месяца назад

Authenticated query containing a TKEY record may cause named to terminate unexpectedly

CVSS3: 6.5
debian
5 месяцев назад

Under certain conditions, `named` may crash when processing a correctl ...

CVSS3: 6.5
github
5 месяцев назад

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the `named` configuration. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

6.5 Medium

CVSS3