Description
An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Service Disruption
Action: Patch Now
AI Analysis

Impact

An attacker may cause a named resolver to abort by exploiting a use‑after‑free bug in the QPCache NOQNAME code. The bug is triggered when the resolver receives multiple DNSSEC‑signed queries from an attacker‑controlled authoritative server, and the responses arrive in a precise order and timing. When the conditions are met the resolver dereferences freed memory, crashes, and stops accepting further queries, leading to a denial of service for any client relying on that resolver.

Affected Systems

ISC BIND 9 is affected. Vulnerable versions include all releases from 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.27‑S1.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, while the EPSS score below 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires control of an authoritative server and precise timing of responses, it is not trivial to exploit in the wild. However, the crash can abruptly terminate the recursive resolver, disrupting services that depend on DNS lookups.

Generated by OpenCVE AI on September 18, 2026 at 00:18 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29 or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade ISC BIND 9 to version 9.20.29 or later, which contains the fix for the use‑after‑free bug.
  • If an immediate upgrade is not possible, block or rate‑limit queries originating from unfamiliar or untrusted authoritative servers, and monitor resolver logs for anomalous DNSSEC‑signed query patterns.
  • Ensure that the resolver is properly fenced and configured to run with the least privileges; consider running named in a sandbox or a minimal privilege container to contain the impact of a crash.

Generated by OpenCVE AI on September 18, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
Description An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the auth responds with a particular sequence of crafted answers, and those answers arrive in a particular order with particular timing, the `named` resolver will encounter a use-after-free bug, and abort. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title qpcache NOQNAME proof use-after-free crashes recursive resolver
First Time appeared Isc
Isc bind
Weaknesses CWE-416
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T18:45:11.717Z

Reserved: 2026-08-12T20:13:09.206Z

Link: CVE-2026-19662

cve-icon Vulnrichment

Updated: 2026-09-17T18:44:59.011Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:04.900

Modified: 2026-09-17T19:16:41.783

Link: CVE-2026-19662

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-16T13:50:10Z

Links: CVE-2026-19662 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses