Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

github логотип

GHSA-cq66-h8mj-77hh

22 дня назад

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-11721

23 дня назад

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-11721

23 дня назад

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-11721

23 дня назад

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-11721

20 дней назад

Cache poisoning possible with label count discrepancy, RRSIG, and wildcards

EPSS: Низкий
debian логотип

CVE-2026-11721

23 дня назад

It is possible for an attacker's zone to respond to a query with an RR ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3484-1

10 дней назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3477-1

10 дней назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3476-1

10 дней назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3452-1

11 дней назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21489-1

15 дней назад

Security update for bind

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3426-1

15 дней назад

Security update for bind

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cq66-h8mj-77hh

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
0%
Низкий
22 дня назад
ubuntu логотип
CVE-2026-11721

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
0%
Низкий
23 дня назад
redhat логотип
CVE-2026-11721

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
0%
Низкий
23 дня назад
nvd логотип
CVE-2026-11721

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is contained. This causes `named` to produce a wildcard name for a zone that is shorter than the attacker's zone, which can result in cache poisoning. For this attack to have any effect, the resolver under attack must have set `synth-from-dnssec yes;` (which is the default). This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

CVSS3: 7.5
0%
Низкий
23 дня назад
msrc логотип
CVE-2026-11721

Cache poisoning possible with label count discrepancy, RRSIG, and wildcards

0%
Низкий
20 дней назад
debian логотип
CVE-2026-11721

It is possible for an attacker's zone to respond to a query with an RR ...

CVSS3: 7.5
0%
Низкий
23 дня назад
suse-cvrf логотип
SUSE-SU-2026:3484-1

Security update for bind

10 дней назад
suse-cvrf логотип
SUSE-SU-2026:3477-1

Security update for bind

10 дней назад
suse-cvrf логотип
SUSE-SU-2026:3476-1

Security update for bind

10 дней назад
suse-cvrf логотип
SUSE-SU-2026:3452-1

Security update for bind

11 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21489-1

Security update for bind

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:3426-1

Security update for bind

15 дней назад

Уязвимостей на страницу