Description
On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly.
This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Published: 2026-09-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw in the query_addnoqnameproof() function, triggered via the DNS64 filter64 path, causes the named daemon to terminate unexpectedly when it receives a maliciously malformed answer from an authoritative server. The resulting crash interrupts DNS resolution services, effectively denying the resolver to clients until the process is restarted. The vulnerability is rooted in improper memory handling (CWE-416) and a lack of input validation (CWE-617).

Affected Systems

ISC BIND 9 is affected. Specifically, vulnerable releases include versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, their -S1 variants, and 9.20.9-S1 through 9.20.27-S1. All configurations that enable the dns64 feature expose the resolver to this flaw.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, but the EPSS score of less than 1% suggests that exploitation is unlikely at the time of this analysis. The flaw is not listed in the CISA KEV catalog, and no publicly documented exploits are known. Likely attack vectors involve an attacker controlling or compromising an authoritative server that returns a malformed response designed to trigger the use‑after‑free. The vulnerability requires that the resolver be actively processing queries via dns64, so it is most relevant to organizations running BIND with that feature enabled.

Generated by OpenCVE AI on September 18, 2026 at 00:17 UTC.

Remediation

Vendor Solution

Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.29, 9.21.26, or 9.20.29-S1.


Vendor Workaround

No workarounds known.


OpenCVE Recommended Actions

  • Upgrade BIND 9 to a patched release such as 9.20.29, 9.21.26, or 9.20.29-S1 to eliminate the use‑after‑free path.
  • If an immediate upgrade is not feasible, disable the dns64 feature or reconfigure the resolver to avoid using dns64 so that malicious replies no longer induce the crash.
  • Configure process supervision or automated restart mechanisms to detect and recover from unexpected exits, and monitor logs for abrupt termination events that may indicate exploitation attempts.

Generated by OpenCVE AI on September 18, 2026 at 00:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6505-1 bind9 security update
History

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-617
References
Metrics threat_severity

None

threat_severity

Important


Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.27-S1.
Title Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path
First Time appeared Isc
Isc bind
Weaknesses CWE-416
CPEs cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*
Vendors & Products Isc
Isc bind
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: isc

Published:

Updated: 2026-09-17T17:38:45.420Z

Reserved: 2026-08-12T20:26:23.829Z

Link: CVE-2026-19666

cve-icon Vulnrichment

Updated: 2026-09-17T17:38:41.163Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T15:17:33.520

Modified: 2026-09-17T18:16:39.403

Link: CVE-2026-19666

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T14:02:30Z

Links: CVE-2026-19666 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T00:30:16Z

Weaknesses