Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5946

Опубликовано: 21 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (IN) — for example, CHAOS or HESIOD, or DNS messages that specify meta-classes (ANY or NONE) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (UPDATE), zone change notifications (NOTIFY), or processing of IN-specific record types in non-IN data — can cause assertion failures in named. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

A flaw was found in the bind component, specifically within the named daemon. This vulnerability allows a remote attacker to send specially crafted Domain Name System (DNS) messages. These messages, which use unusual classes or meta-classes, can trigger assertion failures in the named daemon when processed. Successful exploitation leads to an application level Denial of Service (DoS), making the DNS service unavailable.

Отчет

This is rated as an Important denial of service vulnerability. The named daemon is susceptible to crashes when processing specially crafted DNS messages that utilize non-Internet (IN) classes or meta-classes. This can lead to service unavailability if an attacker sends malicious requests targeting recursion, dynamic updates, zone change notifications, or specific record type processing.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6bindAffected
Red Hat Enterprise Linux 7bindAffected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10bindFixedRHSA-2026:2433808.06.2026
Red Hat Enterprise Linux 8bind9.16FixedRHSA-2026:2336004.06.2026
Red Hat Enterprise Linux 8bindFixedRHSA-2026:2433908.06.2026
Red Hat Enterprise Linux 8bindFixedRHSA-2026:2433908.06.2026
Red Hat Enterprise Linux 9bindFixedRHSA-2026:2436708.06.2026
Red Hat Enterprise Linux 9bind9.18FixedRHSA-2026:2436808.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1287
https://bugzilla.redhat.com/show_bug.cgi?id=2479771bind: BIND: Denial of Service via specially crafted DNS messages

EPSS

Процентиль: 77%
0.01874
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

CVSS3: 7.5
nvd
2 месяца назад

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

CVSS3: 7.5
msrc
2 месяца назад

Invalid handling of CLASS != IN

CVSS3: 7.5
debian
2 месяца назад

Multiple flaws have been identified in `named` related to the handling ...

CVSS3: 7.5
github
2 месяца назад

Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section. Specially crafted requests reaching the affected code paths — recursion, dynamic updates (`UPDATE`), zone change notifications (`NOTIFY`), or processing of `IN`-specific record types in non-`IN` data — can cause assertion failures in `named`. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.48, 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.48-S1, and 9.20.9-S1 through 9.20.22-S1.

EPSS

Процентиль: 77%
0.01874
Низкий

7.5 High

CVSS3